An issue was discovered in Subrion CMS 4.2.1, allowing authenticated adminitrators or moderators with access to the built-in Run SQL Query feature under the SQL Tool admin panel - to gain escalated privileges in the context of the SQL query tool.
The product uses a database table that includes records that should not be accessible to an actor, but it executes a SQL statement with a primary key that can be controlled by that actor.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Subrion_cms | Intelliants | 4.2.1 (including) | 4.2.1 (including) |
When a user can set a primary key to any value, then the user can modify the key to point to unauthorized records. Database access control errors occur when: