Show filters
19 Total Results
Displaying 11-19 of 19
Sort by:
Attacker Value
Unknown
CVE-2020-36608
Disclosure Date: November 02, 2022 (last updated November 08, 2023)
A vulnerability, which was classified as problematic, has been found in Tribal Systems Zenario CMS. Affected by this issue is some unknown functionality of the file admin_organizer.js of the component Error Log Module. The manipulation leads to cross site scripting. The attack may be launched remotely. The name of the patch is dfd0afacb26c3682a847bea7b49ea440b63f3baa. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-212816.
0
Attacker Value
Unknown
CVE-2021-42171
Disclosure Date: March 14, 2022 (last updated February 23, 2025)
Zenario CMS 9.0.54156 is vulnerable to File Upload. The web server can be compromised by uploading and executing a web-shell which can run commands, browse system files, browse local resources, attack other servers, and exploit the local vulnerabilities, and so forth.
0
Attacker Value
Unknown
CVE-2021-41952
Disclosure Date: March 14, 2022 (last updated February 23, 2025)
Zenario CMS 9.0.54156 is vulnerable to Cross Site Scripting (XSS) via upload file to *.SVG. An attacker can send malicious files to victims and steals victim's cookie leads to account takeover. The person viewing the image of a contact can be victim of XSS.
0
Attacker Value
Unknown
CVE-2022-23043
Disclosure Date: February 24, 2022 (last updated February 23, 2025)
Zenario CMS 9.2 allows an authenticated admin user to bypass the file upload restriction by creating a new 'File/MIME Types' using the '.phar' extension. Then an attacker can upload a malicious file, intercept the request and change the extension to '.phar' in order to run commands on the server.
0
Attacker Value
Unknown
CVE-2021-26830
Disclosure Date: April 16, 2021 (last updated February 22, 2025)
SQL Injection in Tribalsystems Zenario CMS 8.8.52729 allows remote attackers to access the database or delete the plugin. This is accomplished via the `ID` input field of ajax.php in the `Pugin library - delete` module.
0
Attacker Value
Unknown
CVE-2021-27673
Disclosure Date: April 15, 2021 (last updated February 22, 2025)
Cross Site Scripting (XSS) in the "admin_boxes.ajax.php" component of Tribal Systems Zenario CMS v8.8.52729 allows remote attackers to execute arbitrary code by injecting arbitrary HTML into the "cID" parameter when creating a new HTML component.
0
Attacker Value
Unknown
CVE-2021-27672
Disclosure Date: April 15, 2021 (last updated February 22, 2025)
SQL Injection in the "admin_boxes.ajax.php" component of Tribal Systems Zenario CMS v8.8.52729 allows remote attackers to obtain sesnitive database information by injecting SQL commands into the "cID" parameter when creating a new HTML component.
0
Attacker Value
Unknown
CVE-2018-18420
Disclosure Date: October 19, 2018 (last updated November 27, 2024)
Cross-Site Request Forgery (CSRF) vulnerability was discovered in the 8.3 version of Zenario Content Management System via the admin/organizer.ajax.php?path=zenario__content%2Fpanels%2Fcontent URI.
0
Attacker Value
Unknown
CVE-2018-5960
Disclosure Date: January 22, 2018 (last updated November 26, 2024)
Zenario v7.1 - v7.6 has SQL injection via the `Name` input field of organizer.php or admin_boxes.ajax.php in the `Categories - Edit` module.
0