CRITICAL9.8
GHSA-rgg3-3wh7-w935
Unrestricted Upload of File with Dangerous Type in Zenario CMS
Quick fix
GHSA-rgg3-3wh7-w935 — tribalsystems/zenario: upgrade to the fixed version with the command below.
composer require tribalsystems/zenario:^9.0.55143Details
Zenario CMS 9.0.54156 is vulnerable to File Upload. The web server can be compromised by uploading and executing a web-shell which can run commands, browse system files, browse local resources, attack other servers, and exploit the local vulnerabilities, and so forth.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/tribalsystems/zenario
Introduced in:
0Fixed in: 9.0.55143Fix
composer require tribalsystems/zenario:^9.0.55143References
- https://nvd.nist.gov/vuln/detail/CVE-2021-42171[ADVISORY]
- https://github.com/hieuminhnv/Zenario-CMS-9.0-last-version/issues/2[WEB]
- https://github.com/TribalSystems/Zenario/commit/4566d8a9ac6755f098b3373252fdb17754a77007[WEB]
- https://github.com/TribalSystems/Zenario[PACKAGE]
- https://github.com/TribalSystems/Zenario/releases/tag/9.0.55141[WEB]
- https://minhnq22.medium.com/file-upload-to-rce-on-zenario-9-0-54156-cms-fa05fcc6cf74[WEB]
- http://packetstormsecurity.com/files/166617/Zenario-CMS-9.0.54156-Remote-Code-Execution.html[WEB]