CVE-2022-23043

HIGH

Tribalsystems Zenario < 9.2.55826 - Unrestricted File Upload

Title source: rule
STIX 2.1

Description

Zenario CMS 9.2 allows an authenticated admin user to bypass the file upload restriction by creating a new 'File/MIME Types' using the '.phar' extension. Then an attacker can upload a malicious file, intercept the request and change the extension to '.phar' in order to run commands on the server.

References (2)

Core 2
Core References
Exploit, Patch, Third Party Advisory x_refsource_misc
https://fluidattacks.com/advisories/simone/
Patch, Release Notes, Third Party Advisory x_refsource_misc
https://github.com/TribalSystems/Zenario/releases/tag/9.2.55826

Scores

CVSS v3 7.2
EPSS 0.0058
EPSS Percentile 68.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-434
Status published
Products (2)
tribalsystems/zenario 9.2
tribalsystems/zenario 0 - 9.2.55826Packagist
Published Feb 24, 2022
Tracked Since Feb 18, 2026