CVE Database
/

CVE-2022-23043

Back to search

CVE-2022-23043

Published: Feb 22, 2022

Modified: Aug 3, 2024

PUBLISHED

Description

Zenario CMS 9.2 allows an authenticated admin user to bypass the file upload restriction by creating a new 'File/MIME Types' using the '.phar' extension. Then an attacker can upload a malicious file, intercept the request and change the extension to '.phar' in order to run commands on the server.

VendorProductVersions

n/a

Zenario CMS

affected
9.2

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now