CRITICAL9.8
GHSA-4p38-rc98-cr39
Zenario CMS is vulnerable to Remote Code Execution (RCE).
Quick fix
GHSA-4p38-rc98-cr39 — tribalsystems/zenario: upgrade to the fixed version with the command below.
composer require tribalsystems/zenario:^9.0.57473Details
Zenario CMS 9.3.57186 is vulnerable to RCE.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/tribalsystems/zenario
Introduced in:
0Fixed in: 9.0.57473Fix
composer require tribalsystems/zenario:^9.0.57473References
- https://nvd.nist.gov/vuln/detail/CVE-2022-44136[ADVISORY]
- https://github.com/TribalSystems/Zenario/commit/4f95a557af3c0b82e448a6ff8f4c167525972e4a[WEB]
- https://com0t.github.io/zenar.io/2022/10/18/Unauthent-RCE-Zenar.io~9.3.html[WEB]
- https://github.com/TribalSystems/Zenario[PACKAGE]
- https://github.com/TribalSystems/Zenario/compare/9.0.55141...9.0.57473[WEB]
- https://github.com/TribalSystems/Zenario/releases/tag/9.0.57473[WEB]