Описание
Zenario uses Twig filters insecurely in the Twig Snippet plugin
Zenario before 9.5.60437 uses Twig filters insecurely in the Twig Snippet plugin, and in the site-wide HEAD and BODY elements, enabling code execution by a designer or an administrator.
Пакеты
Наименование
tribalsystems/zenario
composer
Затронутые версииВерсия исправления
< 9.5.60437
9.5.60437
Связанные уязвимости
CVSS3: 9.8
nvd
почти 2 года назад
Zenario before 9.5.60437 uses Twig filters insecurely in the Twig Snippet plugin, and in the site-wide HEAD and BODY elements, enabling code execution by a designer or an administrator.