PT-2022-11550 · Unknown · Zenario Cms

Hieuminhnv

·

Published

2022-03-14

·

Updated

2022-05-24

·

CVE-2021-42171

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Zenario CMS version 9.0.54156
Description The issue allows an attacker to compromise the web server by uploading and executing a web-shell, which can be used to run commands, browse system files, browse local resources, attack other servers, and exploit local vulnerabilities.
Recommendations For Zenario CMS version 9.0.54156, consider restricting file upload capabilities to prevent the execution of malicious scripts until a fix is available. As a temporary workaround, monitor file uploads closely and restrict access to sensitive system files and resources.

Exploit

Fix

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-42171
GHSA-RGG3-3WH7-W935

Affected Products

Zenario Cms