PT-2024-25915 · Zenario+1 · Zenario+1

Larchik

·

Published

2024-05-04

·

Updated

2024-07-03

·

CVE-2024-34461

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Zenario versions prior to 9.5.60437
Description The issue is related to the insecure use of Twig filters in the Twig Snippet plugin and in the site-wide HEAD and BODY elements, allowing code execution by a designer or an administrator.
Recommendations For versions prior to 9.5.60437, update to version 9.5.60437 or later to resolve the issue. As a temporary workaround, consider restricting access to the Twig Snippet plugin and the site-wide HEAD and BODY elements to minimize the risk of exploitation.

Fix

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2024-34461
GHSA-HR2R-W6WC-25PV

Affected Products

Twig Snippet Plugin
Zenario