CVE-2018-14836: Subrion CMS
Medium severity, CVSS 6.5. EPSS: 1% chance of exploitation in the next 30 days.
Subrion 4.2.1 is vulnerable to Improper Access control because user groups not having access to the Admin panel are able to access it (but not perform actions) if the Guests user group has access to the Admin panel.
Affected products
- Subrion Subrion CMS: version 4.2.1 only
Published 2018-08-02. Last modified 2026-06-17.