Published | 2017-01-20 08:59:00 |
---|---|
Last Modified | 2017-01-20 15:57:16 |
AKA | CVE-2017-5543 |
Summary | includes/classes/ia.core.users.php in Subrion CMS 4.0.5 allows remote attackers to conduct PHP Object Injection attacks via crafted serialized data in a salt cookie in a login request. |
CVSS Score | 7.5 |
CVSS Source | http://nvd.nist.gov |
Access Vector | Local | Adjacent | Network |
---|---|---|---|
Access Complexity | Low | Medium | High |
Authentication | None | Single | Multiple |
Confidentiality | None | Partial | Complete |
Integrity | None | Partial | Complete |
Availability | None | Partial | Complete |
Type | Content |
---|---|
Vendor Advisory | https://github.com/intelliants/subrion/issues/297 |