VDB
Sign up
CRITICAL9.8

GHSA-rgg3-3wh7-w935

Unrestricted Upload of File with Dangerous Type in Zenario CMS

Quick fix

GHSA-rgg3-3wh7-w935 — tribalsystems/zenario: upgrade to the fixed version with the command below.

composer require tribalsystems/zenario:^9.0.55143

Details

Zenario CMS 9.0.54156 is vulnerable to File Upload. The web server can be compromised by uploading and executing a web-shell which can run commands, browse system files, browse local resources, attack other servers, and exploit the local vulnerabilities, and so forth.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/tribalsystems/zenario
Introduced in: 0Fixed in: 9.0.55143
Fixcomposer require tribalsystems/zenario:^9.0.55143

References