CVE-2018-19422: Intelliants Subrion CMS

High severity, CVSS 7.2. EPSS: 64.3% chance of exploitation in the next 30 days.

/panel/uploads in Subrion CMS 4.2.1 allows remote attackers to execute arbitrary PHP code via a .pht or .phar file, because the .htaccess file omits these.

Affected products

Published 2018-11-21. Last modified 2026-06-17.