PatchSiren cyber security CVE debrief
CVE-2017-5543 Intelliants CVE debrief
CVE-2017-5543 affects Subrion CMS 4.0.5. The public description says includes/classes/ia.core.users.php can allow remote attackers to conduct PHP Object Injection via crafted serialized data in a salt cookie sent with a login request. NVD rates the issue Critical with CVSS 3.0 vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, meaning a network-reachable attack with no privileges or user interaction and high impact if successful. NVD maps the weakness to CWE-94.
- Vendor
- Intelliants
- Product
- Subrion
- CVSS
- CRITICAL 9.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2017-01-20
- Original CVE updated
- 2026-05-13
- Advisory published
- 2017-01-20
- Advisory updated
- 2026-05-13
Who should care
Administrators and security teams running Subrion CMS 4.0.5 should treat this as high priority, especially if the login endpoint is reachable from untrusted networks. Incident responders should also review any exposed or legacy Subrion installations for signs of abuse.
Technical summary
The vulnerable code path is identified in includes/classes/ia.core.users.php. According to the supplied NVD description, a login request can carry a salt cookie containing crafted serialized data that triggers PHP object injection. NVD classifies the weakness as CWE-94 and assigns a critical network-exploitable CVSS profile with no authentication or user interaction required.
Defensive priority
Immediate
Recommended defensive actions
- Inventory all Subrion CMS deployments and confirm whether any instance is running version 4.0.5.
- Apply the vendor-referenced fix or upgrade path associated with the issue tracker entry as soon as possible.
- If patching cannot be done immediately, restrict access to the login interface to trusted networks or administrative sources only.
- Monitor authentication logs and HTTP request telemetry for unusual login attempts or unexpected serialized cookie values.
- If compromise is suspected, preserve logs, investigate affected hosts, and rotate credentials and secrets used by the application.
Evidence notes
The supplied CVE and NVD data identify Subrion CMS 4.0.5 as vulnerable and describe remote PHP object injection through crafted serialized data in a salt cookie during login. The NVD metadata assigns CVSS 3.0 AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H and CWE-94. References in the source corpus include an official CVE record, an official NVD detail page, a SecurityFocus advisory entry, and a GitHub issue-tracker reference tagged as Patch and Third Party Advisory. No KEV entry is supplied.
Sources and references
Verified primary and authoritative sources
-
CVE-2017-5543 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2017-5543
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2017-5543 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2017-5543
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://github.com/intelliants/subrion/issues/297
[email protected] - Issue Tracking, Patch, Third Party Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.