{"id":"CVE-2021-27672","aliases":[],"url":"https://o3.security/vulnerability/CVE-2021-27672","summary":"SQL Injection in tribalsystems/zenario","details":"SQL Injection in the \"admin_boxes.ajax.php\" component of Tribal Systems Zenario CMS v8.8.52729 allows remote attackers to obtain sesnitive database information by injecting SQL commands into the \"cID\" parameter when creating a new HTML component.","published":"2021-06-08T20:12:02Z","modified":"2023-11-08T04:05:25.402962Z","cvss":{"score":4.9,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[{"ecosystem":"Packagist","name":"tribalsystems/zenario","fixedVersion":"8.8.53370"}],"fix":{"url":"https://github.com/TribalSystems/Zenario/commit/2c82a4d126c8446106347ef603b157f2d4175fd1","label":"TribalSystems/Zenario@2c82a4d"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2021-27672"},{"type":"WEB","url":"https://github.com/TribalSystems/Zenario/commit/2c82a4d126c8446106347ef603b157f2d4175fd1"},{"type":"WEB","url":"https://deadsh0t.medium.com/blind-error-based-authenticated-sql-injection-on-zenario-8-8-52729-cms-d4705534df38"},{"type":"WEB","url":"https://github.com/TribalSystems/Zenario/releases/tag/8.8.53370"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2023-11-08T04:05:25.402962Z"}}