Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-28990 | An issue was discovered in Subrion CMS 4.2.1, allowing authenticated adminitrators or moderators with access to the built-in Run SQL Query feature under the SQL Tool admin panel - to gain escalated privileges in the context of the SQL query tool. |
Github GHSA |
GHSA-h8wv-vv58-468h | Subrion CMS: Authenticated administrators are able to gain escalated access through Run SQL Query tool |
| Link | Providers |
|---|---|
| https://github.com/intelliants/subrion/issues/913 |
|
Tue, 25 Nov 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
cvssV3_1
|
Thu, 02 Oct 2025 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Intelliants
Intelliants subrion Cms |
|
| CPEs | cpe:2.3:a:intelliants:subrion_cms:4.2.1:*:*:*:*:*:*:* | |
| Vendors & Products |
Intelliants
Intelliants subrion Cms |
Fri, 12 Sep 2025 08:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Subrion
Subrion cms |
|
| Vendors & Products |
Subrion
Subrion cms |
Thu, 11 Sep 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-566 | |
| Metrics |
cvssV3_1
|
Thu, 11 Sep 2025 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An issue was discovered in Subrion CMS 4.2.1, allowing authenticated adminitrators or moderators with access to the built-in Run SQL Query feature under the SQL Tool admin panel - to gain escalated privileges in the context of the SQL query tool. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-11-25T14:14:00.515Z
Reserved: 2025-08-17T00:00:00.000Z
Link: CVE-2025-56556
Updated: 2025-09-11T20:36:25.901Z
Status : Modified
Published: 2025-09-11T19:15:32.660
Modified: 2025-11-25T15:15:52.147
Link: CVE-2025-56556
No data.
OpenCVE Enrichment
Updated: 2025-09-12T08:02:32Z
EUVD
Github GHSA