Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Qobiljon Oblaqulov

#43515of 56,334
6.5Total CVSS
Vulnerabilities · 1
PT-2026-70148
6.5
2026-08-11
Intelliants · Subrion Cms · CVE-2026-72604
**Name of the Vulnerable Software and Affected Versions** Intelliants Subrion CMS versions prior to 4.2.2 **Description** An authenticated administrator can delete arbitrary files on the server through the admin panel file deletion endpoint. This occurs because the endpoint passes a user-supplied file path directly to the `unlink()` function without sanitization or path canonicalization. Path canonicalization is the process of converting a file path to its simplest, standard form to prevent bypasses. This flaw allows the deletion of sensitive system files outside the web root, which may lead to server instability or facilitate further attacks. **Recommendations** Update Intelliants Subrion CMS to version 4.2.2 or later.