CVE-2026-96773 | Intelliants Subrion CMS up to 4.2.1 Login Page front/login.php iaUsers::authorize $_SERVER[‘HTTP_REFERER’] redirect
A vulnerability has been found in Intelliants Subrion CMS up to 4.2.1 and classified as problematic. This vulnerability affects the function iaUsers::authorize of the file front/login.php of the component Login Page. This manipulation of the argument $_SERVER[‘HTTP_REFERER’] causes open redirect.
This vulnerability is tracked as CVE-2026-96773. The attack is possible to be carried out remotely. Moreover, an exploit is present.
The vendor was contacted early about this disclosure but did not respond in any way.VulDB Recent EntriesRead More