MEDIUM4.8
GHSA-3636-hx62-pv26
Zenario allows authenticated admin users to upload PDF files containing malicious code
Details
Zenario 9.7.61188 allows authenticated admin users to upload PDF files containing malicious code into the target system. If the PDF file is accessed through the website, it can trigger a Cross Site Scripting (XSS) attack.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/tribalsystems/zenario
Introduced in:
0No fixed version published yet for tribalsystems/zenario (composer). Pin to a known-safe version or switch to an alternative.