SQL Injection in tribalsystems/zenario
Critical severity
GitHub Reviewed
Published
Mar 18, 2022
to the GitHub Advisory Database
•
Updated Jul 6, 2023
Description
Published by the National Vulnerability Database
Apr 16, 2021
Reviewed
May 6, 2021
Published to the GitHub Advisory Database
Mar 18, 2022
Last updated
Jul 6, 2023
SQL Injection in Tribalsystems Zenario CMS 8.8.52729 and prior allows remote attackers to access the database or delete the plugin. This is accomplished via the
ID
input field of ajax.php in thePugin library - delete
module.References