VYPR

Zenario

by Tribalsystems

Source repositories

CVEs (23)

  • CVE-2021-27672MedApr 15, 2021
    risk 0.25cvss 4.9epss 0.01

    SQL Injection in the "admin_boxes.ajax.php" component of Tribal Systems Zenario CMS v8.8.52729 allows remote attackers to obtain sesnitive database information by injecting SQL commands into the "cID" parameter when creating a new HTML component.

  • CVE-2021-41952MedMar 14, 2022
    risk 0.24cvss 4.8epss 0.01

    Zenario CMS 9.0.54156 is vulnerable to Cross Site Scripting (XSS) via upload file to *.SVG. An attacker can send malicious files to victims and steals victim's cookie leads to account takeover. The person viewing the image of a contact can be victim of XSS.

  • CVE-2020-36608LowNov 2, 2022
    risk 0.16cvss 3.5epss 0.00

    A vulnerability, which was classified as problematic, has been found in Tribal Systems Zenario CMS. Affected by this issue is some unknown functionality of the file admin_organizer.js of the component Error Log Module. The manipulation leads to cross site scripting. The attack…

Page 2 of 2