SQL Injection in Tribalsystems Zenario CMS 8.8.52729 and prior allows remote attackers to access the database or delete the plugin. This is accomplished via the ID
input field of ajax.php in the Pugin library - delete
module.
{ "nvd_published_at": "2021-04-16T18:15:00Z", "cwe_ids": [ "CWE-89" ], "severity": "CRITICAL", "github_reviewed": true, "github_reviewed_at": "2021-05-06T22:39:06Z" }