{"id":"CVE-2020-36608","aliases":["GHSA-f92p-f8r2-c87q"],"url":"https://o3.security/vulnerability/CVE-2020-36608","summary":"Tribal Systems Zenario CMS vulnerable to Cross-site Scripting","details":"A vulnerability, which was classified as problematic, has been found in Tribal Systems Zenario CMS. Affected by this issue is some unknown functionality of the file admin_organizer.js of the component Error Log Module. The manipulation leads to cross site scripting. The attack may be launched remotely. The name of the patch is dfd0afacb26c3682a847bea7b49ea440b63f3baa. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-212816.","published":"2022-11-02T19:15:09.807Z","modified":"2026-07-08T20:43:07.383501Z","cvss":{"score":6.1,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"},"epss":{"score":0.00413,"percentile":0.34631,"asOf":"2026-08-23"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"tribalsystems/zenario","fixedVersion":"8.5.51340"}],"fix":{"url":"https://github.com/TribalSystems/Zenario/commit/dfd0afacb26c3682a847bea7b49ea440b63f3baa","label":"TribalSystems/Zenario@dfd0afa"},"references":[{"type":"ADVISORY","url":"https://vuldb.com/?id.212816"},{"type":"FIX","url":"https://github.com/TribalSystems/Zenario/commit/dfd0afacb26c3682a847bea7b49ea440b63f3baa"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-08T20:43:07.383501Z"}}