← Zurück zur CVE-Suche

CVE-2026-71292

Beschreibung

Subrion CMS-s admin grid sorting helper, _gridGetSorting in includes/classes/ia.base.controller.admin.php, whitelists the (ASC/DESC) request parameter via in_array, but falls back to the raw, attacker-supplied GET parameter whenever the requested key is not present in the per-controller whitelist array: , which is then placed into %s with only backtick-quoting and no escaping.

CVSS 7.2EPSS 0.318%Risiko 0.74
Quelle öffnen
Veröffentlicht
2026-08-05 13:24:53
Zuletzt geändert
2026-08-10 12:17:31
Vektor
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H