VDB
Sign up
MEDIUM4.9

GHSA-gxcm-36qw-j29v

SQL Injection in tribalsystems/zenario

Quick fix

GHSA-gxcm-36qw-j29v — tribalsystems/zenario: upgrade to the fixed version with the command below.

composer require tribalsystems/zenario:^8.8.53370

Details

SQL Injection in the "admin_boxes.ajax.php" component of Tribal Systems Zenario CMS v8.8.52729 allows remote attackers to obtain sesnitive database information by injecting SQL commands into the "cID" parameter when creating a new HTML component.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/tribalsystems/zenario
Introduced in: 0Fixed in: 8.8.53370
Fixcomposer require tribalsystems/zenario:^8.8.53370

References