GHSA-gxcm-36qw-j29v
MODERATECVE-2021-27672SQL Injection in the "adminboxes.ajax.php" component of Tribal Systems Zenario CMS v8.8.52729 allows remote attackers to obtain sesnitive database information by injecting SQL commands into the "cID" parameter when creating a new HTML component.
- Affected
- < 8.8.53370
- Fixed in
- 8.8.53370
- Published
- 2021-06-08
- Source
- github