CVE-2021-26830
CRITICALTribalsystems Zenario < 8.8.53370 - SQL Injection
Title source: ruleDescription
SQL Injection in Tribalsystems Zenario CMS 8.8.52729 allows remote attackers to access the database or delete the plugin. This is accomplished via the `ID` input field of ajax.php in the `Pugin library - delete` module.
Exploits (1)
Scores
CVSS v3
9.1
EPSS
0.0126
EPSS Percentile
79.4%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Details
CWE
CWE-89
Status
published
Products (2)
tribalsystems/zenario
8.8.52729
tribalsystems/zenario
0 - 8.8.53370Packagist
Published
Apr 16, 2021
Tracked Since
Feb 18, 2026