Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:38308
HistoryDec 01, 2022 - 4:43 a.m.

Remote Code Execution

2022-12-0104:43:55
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
5
vulnerable
remote attacker
malicious code
file upload
user form module

0.003 Low

EPSS

Percentile

68.8%

tribalsystems/zenario is vulnerable to remote code execution. It is possible for a remote attacker to upload and execute malicious code on the system via the vulnerable handlePluginAJAX function in module_code.php which resides inside User Form module, when the file upload is enabled.

0.003 Low

EPSS

Percentile

68.8%

Related for VERACODE:38308