CVE-2024-45960

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
02/10/2024
Last modified:
03/07/2025

Description

Zenario 9.7.61188 allows authenticated admin users to upload PDF files containing malicious code into the target system. If the PDF file is accessed through the website, it can trigger a Cross Site Scripting (XSS) attack.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:tribalsystems:zenario:9.7.61188:*:*:*:*:*:*:*