CVE-2020-18326: Intelliants Subrion CMS
High severity, CVSS 8.8. EPSS: 2.2% chance of exploitation in the next 30 days.
Cross Site Request Forgery (CSRF) vulnerability exists in Intelliants Subrion CMS v4.2.1 via the Members administrator function, which could let a remote unauthenticated malicious user send an authorised request to victim and successfully create an arbitrary administrator user.
Affected products
- Intelliants Subrion CMS: version 4.2.1 only
Published 2022-03-04. Last modified 2026-07-09.