Lucene search

K
osvGoogleOSV:GHSA-W4F3-7F7C-X652
HistoryMar 18, 2022 - 5:49 p.m.

SQL Injection in tribalsystems/zenario

2022-03-1817:49:01
Google
osv.dev
10
sql
injection
tribalsystems
zenario
cms
remote attackers
database access
plugin deletion
id input
ajax.php
pugin library - delete

EPSS

0.002

Percentile

54.0%

SQL Injection in Tribalsystems Zenario CMS 8.8.52729 and prior allows remote attackers to access the database or delete the plugin. This is accomplished via the ID input field of ajax.php in the Pugin library - delete module.

EPSS

0.002

Percentile

54.0%

Related for OSV:GHSA-W4F3-7F7C-X652