HIGH8.8
GHSA-jf5f-h3wr-j666
SQL Injection in Zenario 7.1-7.6
Details
Zenario v7.1 - v7.6 has SQL injection via the `Name` input field of organizer.php or admin_boxes.ajax.php in the `Categories - Edit` module.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/tribalsystems/zenario
Introduced in:
7.1No fixed version published yet for tribalsystems/zenario (composer). Pin to a known-safe version or switch to an alternative.