HIGH7.2
GHSA-6r86-2jm9-9mh4
File upload restriction bypass in Zenario CMS
Quick fix
GHSA-6r86-2jm9-9mh4 — tribalsystems/zenario: upgrade to the fixed version with the command below.
composer require tribalsystems/zenario:^9.2.55826Details
Zenario CMS 9.2 allows an authenticated admin user to bypass the file upload restriction by creating a new 'File/MIME Types' using the '.phar' extension. Then an attacker can upload a malicious file, intercept the request and change the extension to '.phar' in order to run commands on the server.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/tribalsystems/zenario
Introduced in:
0Fixed in: 9.2.55826Fix
composer require tribalsystems/zenario:^9.2.55826References
- https://nvd.nist.gov/vuln/detail/CVE-2022-23043[ADVISORY]
- https://github.com/TribalSystems/Zenario/commit/f0682d22688d9921dc0dfd6e858900ebf2706f19[WEB]
- https://fluidattacks.com/advisories/simone[WEB]
- https://github.com/TribalSystems/Zenario[PACKAGE]
- https://github.com/TribalSystems/Zenario/releases/tag/9.2.55826[WEB]