PT-2024-31856 · Zenario · Zenario

Published

2024-10-02

·

Updated

2025-07-03

·

CVE-2024-45960

CVSS v3.1

4.8

Medium

VectorAV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Zenario version 9.7.61188
Description The issue allows authenticated admin users to upload PDF files containing malicious code into the target system. If the PDF file is accessed through the website, it can trigger a Cross Site Scripting (XSS) attack.
Recommendations For Zenario version 9.7.61188, consider restricting the upload of PDF files by authenticated admin users until a patch is available. As a temporary workaround, limit access to the PDF upload feature to minimize the risk of exploitation.

Exploit

Fix

XSS

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2024-45960
GHSA-3636-HX62-PV26

Affected Products

Zenario