edhunter484.medium.com
https://edhunter484.medium.com/blind-sql-injection-on-zenario-cms-b58b6820c32d CVE-2021-26830
CRITICAL
SQL Injection in tribalsystems/zenario
Record summary
CVE-2021-26830 has a selected CVSS score of 9.1 (critical); EIP currently links 1 catalogued exploit.
Description
SQL Injection in Tribalsystems Zenario CMS 8.8.52729 allows remote attackers to access the database or delete the plugin. This is accomplished via the `ID` input field of ajax.php in the `Pugin library - delete` module.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
tribalsystems/zenarioBrowse Packagist / tribalsystems/zenario | GitHub Advisory | Before 8.8.53370 · Fixed in 8.8.53370 | affected |
Proofs of concept
1Catalogued exploits
ExploitDBZenario CMS 8.8.53370 - 'id' Blind SQL InjectionExploitDB exploitby Balaji AyyasamyNot analyzed1 file
References
5github.com
https://github.com/TribalSystems/Zenario/commit/2c82a4d126c8446106347ef603b157f2d4175fd1 github.comConfirmation
https://github.com/TribalSystems/Zenario/releases/tag/8.8.53370 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2021-26830 exploit-db.com
https://www.exploit-db.com/exploits/49642