VYPR
Moderate severityNVD Advisory· Published Nov 16, 2022· Updated Apr 30, 2025

CVE-2022-44070

CVE-2022-44070

Description

Zenario CMS 9.3.57186 is vulnerable to Cross Site Scripting (XSS) via News articles.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Zenario CMS 9.3.57186 is vulnerable to stored XSS via News articles, allowing attackers to inject arbitrary JavaScript.

Vulnerability

Description Zenario CMS version 9.3.57186 contains a stored cross-site scripting (XSS) vulnerability in the News articles functionality [1]. The root cause is insufficient sanitization of user-supplied input in the Summary and Main Content fields when creating or editing news articles. This allows an authenticated attacker to inject arbitrary HTML and JavaScript code that is stored on the server [2].

Exploitation

To exploit this vulnerability, an attacker must have a valid account with access to the News section. The attacker can inject a payload, such as an EMBED element with a base64-encoded SVG containing a script, into the Summary or Main Content fields. Upon saving, the payload is stored and executed in the browser of any user viewing the affected news article [2]. No special network position is required beyond standard web access.

Impact

Successful exploitation allows the attacker to execute arbitrary JavaScript in the context of the victim's session. This can lead to session hijacking, defacement, or theft of sensitive information displayed in the CMS. The attack is particularly dangerous because it affects all users who view the malicious article, including administrators [1][2].

Mitigation

As of publication, no official patch has been released by Zenario. The vulnerability was reported via GitHub issues [2]. Until a fix is available, administrators should restrict access to the News article editor to trusted users and consider disabling the feature if not needed.

AI Insight generated on May 21, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
tribalsystems/zenarioPackagist
<= 9.3.57186

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.