Description
SQL Injection in Tribalsystems Zenario CMS 8.8.52729 allows remote attackers to access the database or delete the plugin. This is accomplished via the `ID` input field of ajax.php in the `Pugin library - delete` module.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-1561 | SQL Injection in Tribalsystems Zenario CMS 8.8.52729 allows remote attackers to access the database or delete the plugin. This is accomplished via the `ID` input field of ajax.php in the `Pugin library - delete` module. |
Github GHSA |
GHSA-w4f3-7f7c-x652 | SQL Injection in tribalsystems/zenario |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-03T20:33:41.264Z
Reserved: 2021-02-05T00:00:00.000Z
Link: CVE-2021-26830
No data.
Status : Modified
Published: 2021-04-16T18:15:13.403
Modified: 2024-11-21T05:56:52.563
Link: CVE-2021-26830
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA