{ "id": "CVE-2024-25400", "sourceIdentifier": "cve@mitre.org", "published": "2024-02-27T16:15:46.517", "lastModified": "2024-11-21T09:00:44.967", "vulnStatus": "Awaiting Analysis", "cveTags": [ { "sourceIdentifier": "cve@mitre.org", "tags": [ "disputed" ] } ], "descriptions": [ { "lang": "en", "value": "Subrion CMS 4.2.1 is vulnerable to SQL Injection via ia.core.mysqli.php. NOTE: this is disputed by multiple third parties because it refers to an HTTP request to a PHP file that only contains a class, without any mechanism for accepting external input, and the reportedly vulnerable method is not present in the file." }, { "lang": "es", "value": "Subrion CMS 4.2.1 es vulnerable a la inyecci\u00f3n SQL a trav\u00e9s de ia.core.mysqli.php." } ], "metrics": {}, "references": [ { "url": "https://github.com/intelliants/subrion/issues/910", "source": "cve@mitre.org" }, { "url": "https://github.com/intelliants/subrion/issues/910", "source": "af854a3a-2127-422b-91ae-364da2661108" } ] }