VDB
Sign up
MEDIUM4.8

GHSA-3636-hx62-pv26

Zenario allows authenticated admin users to upload PDF files containing malicious code

Details

Zenario 9.7.61188 allows authenticated admin users to upload PDF files containing malicious code into the target system. If the PDF file is accessed through the website, it can trigger a Cross Site Scripting (XSS) attack.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/tribalsystems/zenario
Introduced in: 0

No fixed version published yet for tribalsystems/zenario (composer). Pin to a known-safe version or switch to an alternative.

References