Tribal Systems Zenario CMS Remember Me session fixiation
Description
A vulnerability, which was classified as problematic, has been found in Tribal Systems Zenario CMS 9.3.57595. This issue affects some unknown processing of the component Remember Me Handler. The manipulation leads to session fixiation. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-214589 was assigned to this vulnerability.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Session fixation in Zenario CMS 9.3.57595 Remember Me handler allows remote attackers to hijack authenticated sessions.
Vulnerability
CVE-2022-4231 describes a session fixation vulnerability in Tribal Systems Zenario CMS version 9.3.57595. The flaw resides in the Remember Me Handler, where the session identifier (PHPSESSID-Zenario) is not regenerated after a user logs out and logs back in when the "Remember me" option is active [1][2]. This allows an attacker to force a known session ID onto a victim and then wait for the victim to authenticate, thereby hijacking the session.
Exploitation
An attacker can remotely exploit this issue without authentication. By tricking a user into using a pre-set session ID (e.g., via a crafted link or by setting the cookie), the attacker can then monitor that session. When the victim logs in with the "Remember me" option, the session ID remains unchanged, giving the attacker access to the authenticated session [2]. The exploit has been publicly disclosed, increasing the risk of active attacks.
Impact
Successful exploitation enables an attacker to gain unauthorized access to the victim's authenticated session, potentially leading to account takeover and access to sensitive data or administrative functions within the CMS [1].
Mitigation
As of the publication date, no official patch has been confirmed. Users are advised to disable the "Remember me" feature as a workaround or monitor vendor updates for a fix [1][2].
AI Insight generated on May 21, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
tribalsystems/zenarioPackagist | <= 9.3.57595 | — |
Affected products
2- Tribal Systems/Zenario CMSv5Range: 9.3.57595
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4News mentions
0No linked articles in our index yet.