VDB
Sign up
CRITICAL9.1

GHSA-w4f3-7f7c-x652

SQL Injection in tribalsystems/zenario

Quick fix

GHSA-w4f3-7f7c-x652 — tribalsystems/zenario: upgrade to the fixed version with the command below.

composer require tribalsystems/zenario:^8.8.53370

Details

SQL Injection in Tribalsystems Zenario CMS 8.8.52729 and prior allows remote attackers to access the database or delete the plugin. This is accomplished via the `ID` input field of ajax.php in the `Pugin library - delete` module.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/tribalsystems/zenario
Introduced in: 0Fixed in: 8.8.53370
Fixcomposer require tribalsystems/zenario:^8.8.53370

References