PatchSiren

intelliants CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH intelliants CVE published 2026-08-05

CVE-2026-71292

The Subrion CMS's admin grid sorting helper is vulnerable to SQL injection due to improper handling of the `sort` GET parameter. An authenticated admin session can inject arbitrary SQL to extract database contents, including administrator password hashes. This occurs because a backtick in the payload breaks out of the identifier context, allowing error-based extraction via EXTRACTVALUE or time-based extra [truncated]

LOW Intelliants CVE published 2026-06-15

CVE-2026-12202

A vulnerability has been found in Intelliants Subrion CMS up to 4.0.3. Affected by this issue is some unknown functionality of the component Blocks Endpoint. Such manipulation of the argument CSS class name leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respon [truncated]

CRITICAL Intelliants CVE published 2017-01-20

CVE-2017-5543

CVE-2017-5543 affects Subrion CMS 4.0.5. The public description says includes/classes/ia.core.users.php can allow remote attackers to conduct PHP Object Injection via crafted serialized data in a salt cookie sent with a login request. NVD rates the issue Critical with CVSS 3.0 vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, meaning a network-reachable attack with no privileges or user interaction and high imp [truncated]