CVE-2021-26830
Severity CVSS v4.0:
Pending analysis
Type:
CWE-89
SQL Injection
Publication date:
16/04/2021
Last modified:
19/04/2021
Description
SQL Injection in Tribalsystems Zenario CMS 8.8.52729 allows remote attackers to access the database or delete the plugin. This is accomplished via the `ID` input field of ajax.php in the `Pugin library - delete` module.
Impact
Base Score 3.x
9.10
Severity 3.x
CRITICAL
Base Score 2.0
6.40
Severity 2.0
MEDIUM
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:a:tribalsystems:zenario:8.8.52729:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page