VDB
Sign up
HIGH7.2

GHSA-6r86-2jm9-9mh4

File upload restriction bypass in Zenario CMS

Quick fix

GHSA-6r86-2jm9-9mh4 — tribalsystems/zenario: upgrade to the fixed version with the command below.

composer require tribalsystems/zenario:^9.2.55826

Details

Zenario CMS 9.2 allows an authenticated admin user to bypass the file upload restriction by creating a new 'File/MIME Types' using the '.phar' extension. Then an attacker can upload a malicious file, intercept the request and change the extension to '.phar' in order to run commands on the server.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/tribalsystems/zenario
Introduced in: 0Fixed in: 9.2.55826
Fixcomposer require tribalsystems/zenario:^9.2.55826

References