TribalSystems/Zenario

TribalSystems/Zenario

Releases155
Frequency3 weeks 4 days
Last Release
Stars34
Zenario is a web-based content management system (CMS) for sites with one or many languages. It is simple to use, and can grow with your requirements.

CVE History

CVEPublishedCVSS v3CVSS v2
3.5 LOW

A vulnerability, which was classified as problematic, has been found in Tribal Systems Zenario CMS. Affected by this issue is some unknown functionality of the file admin_organizer.js of the component Error Log Module. The manipulation leads to cross site scripting. The attack may be launched remotely. The name of the patch is dfd0afacb26c3682a847bea7b49ea440b63f3baa. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-212816.

7.2 HIGH6.5 MEDIUM

Zenario CMS 9.2 allows an authenticated admin user to bypass the file upload restriction by creating a new 'File/MIME Types' using the '.phar' extension. Then an attacker can upload a malicious file, intercept the request and change the extension to '.phar' in order to run commands on the server.

9.1 CRITICAL6.4 MEDIUM

SQL Injection in Tribalsystems Zenario CMS 8.8.52729 allows remote attackers to access the database or delete the plugin. This is accomplished via the `ID` input field of ajax.php in the `Pugin library - delete` module.