VDB
Sign up
HIGH8.8

GHSA-jf5f-h3wr-j666

SQL Injection in Zenario 7.1-7.6

Details

Zenario v7.1 - v7.6 has SQL injection via the `Name` input field of organizer.php or admin_boxes.ajax.php in the `Categories - Edit` module.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/tribalsystems/zenario
Introduced in: 7.1

No fixed version published yet for tribalsystems/zenario (composer). Pin to a known-safe version or switch to an alternative.

References