CVE-2022-23043

HIGH7.2EPSS 0.58%

File upload restriction bypass in Zenario CMS

Published: 2/25/2022Modified: 2/19/2024
Also known as:GHSA-6r86-2jm9-9mh4

Description

Zenario CMS 9.2 allows an authenticated admin user to bypass the file upload restriction by creating a new 'File/MIME Types' using the '.phar' extension. Then an attacker can upload a malicious file, intercept the request and change the extension to '.phar' in order to run commands on the server.

Affected packages (1)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1HIGH7.2CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

References (5)