VDB
Sign up
MEDIUM4.8

GHSA-8hcm-jj4x-4gmr

reflected XSS in tribalsystems/zenario

Quick fix

GHSA-8hcm-jj4x-4gmr — tribalsystems/zenario: upgrade to the fixed version with the command below.

composer require tribalsystems/zenario:^8.8.53370

Details

Reflected XSS in the "admin_boxes.ajax.php" component of Tribal Systems Zenario CMS v8.8.52729 allows remote attackers to execute arbitrary code by injecting into the "cID" parameter when creating a new HTML component.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/tribalsystems/zenario
Introduced in: 0Fixed in: 8.8.53370
Fixcomposer require tribalsystems/zenario:^8.8.53370

References