CRITICAL9.1
GHSA-w4f3-7f7c-x652
SQL Injection in tribalsystems/zenario
Quick fix
GHSA-w4f3-7f7c-x652 — tribalsystems/zenario: upgrade to the fixed version with the command below.
composer require tribalsystems/zenario:^8.8.53370Details
SQL Injection in Tribalsystems Zenario CMS 8.8.52729 and prior allows remote attackers to access the database or delete the plugin. This is accomplished via the `ID` input field of ajax.php in the `Pugin library - delete` module.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/tribalsystems/zenario
Introduced in:
0Fixed in: 8.8.53370Fix
composer require tribalsystems/zenario:^8.8.53370References
- https://nvd.nist.gov/vuln/detail/CVE-2021-26830[ADVISORY]
- https://github.com/TribalSystems/Zenario/commit/2c82a4d126c8446106347ef603b157f2d4175fd1[WEB]
- https://edhunter484.medium.com/blind-sql-injection-on-zenario-cms-b58b6820c32d[WEB]
- https://github.com/TribalSystems/Zenario/releases/tag/8.8.53370[WEB]
- https://www.exploit-db.com/exploits/49642[WEB]