GHSA-8hcm-jj4x-4gmr
Dashboard / Vulnerabilities / GHSA-8hcm-jj4x-4gmr
Summary: reflected XSS in tribalsystems/zenario
Details: Reflected XSS in the "admin_boxes.ajax.php" component of Tribal Systems Zenario CMS v8.8.52729 allows remote attackers to execute arbitrary code by injecting into the "cID" parameter when creating a new HTML component.
References: https://nvd.nist.gov/vuln/detail/CVE-2021-27673, https://deadsh0t.medium.com/blind-error-based-authenticated-sql-injection-on-zenario-8-8-52729-cms-d4705534df38, https://github.com/TribalSystems/Zenario, https://github.com/TribalSystems/Zenario/releases/tag/8.8.53370, http://packetstormsecurity.com/files/163083/Zenario-CMS-8.8.52729-SQL-Injection.html
Affected packages
Package
Name: tribalsystems/zenario
Purl: pkg:composer/tribalsystems/zenario
Affected ranges
Type: ECOSYSTEM
Events:
