CVE-2018-14836
Summary
| CVE | CVE-2018-14836 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-08-02 00:29:00 UTC |
| Updated | 2019-10-03 00:03:00 UTC |
| Description | Subrion 4.2.1 is vulnerable to Improper Access control because user groups not having access to the Admin panel are able to access it (but not perform actions) if the Guests user group has access to the Admin panel. |
Risk And Classification
Problem Types: CWE-269
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Subrion | Subrion Cms | 4.2.1 | All | All | All |
| Application | Subrion | Subrion Cms | 4.2.1 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Broken Authentication (Unauthorized partial access to admin panel) · Issue #762 · intelliants/subrion · GitHub | MISC | github.com | Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.