Описание
SQL Injection in tribalsystems/zenario
SQL Injection in Tribalsystems Zenario CMS 8.8.52729 and prior allows remote attackers to access the database or delete the plugin. This is accomplished via the ID input field of ajax.php in the Pugin library - delete module.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2021-26830
- https://github.com/TribalSystems/Zenario/commit/2c82a4d126c8446106347ef603b157f2d4175fd1
- https://edhunter484.medium.com/blind-sql-injection-on-zenario-cms-b58b6820c32d
- https://github.com/TribalSystems/Zenario/releases/tag/8.8.53370
- https://www.exploit-db.com/exploits/49642
Пакеты
Наименование
tribalsystems/zenario
composer
Затронутые версииВерсия исправления
< 8.8.53370
8.8.53370
Связанные уязвимости
CVSS3: 9.1
nvd
почти 5 лет назад
SQL Injection in Tribalsystems Zenario CMS 8.8.52729 allows remote attackers to access the database or delete the plugin. This is accomplished via the `ID` input field of ajax.php in the `Pugin library - delete` module.