PT-2022-11550 · Unknown · Zenario Cms
Hieuminhnv
·
Published
2022-03-14
·
Updated
2022-05-24
·
CVE-2021-42171
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Zenario CMS version 9.0.54156
Description
The issue allows an attacker to compromise the web server by uploading and executing a web-shell, which can be used to run commands, browse system files, browse local resources, attack other servers, and exploit local vulnerabilities.
Recommendations
For Zenario CMS version 9.0.54156, consider restricting file upload capabilities to prevent the execution of malicious scripts until a fix is available. As a temporary workaround, monitor file uploads closely and restrict access to sensitive system files and resources.
Exploit
Fix
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Zenario Cms