{"id":"CVE-2021-27673","aliases":[],"url":"https://o3.security/vulnerability/CVE-2021-27673","summary":"reflected XSS in tribalsystems/zenario","details":"Reflected XSS in the \"admin_boxes.ajax.php\" component of Tribal Systems Zenario CMS v8.8.52729 allows remote attackers to execute arbitrary code by injecting into the \"cID\" parameter when creating a new HTML component.","published":"2021-06-08T20:11:40Z","modified":"2024-02-16T08:17:21.867289Z","cvss":{"score":4.8,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[{"ecosystem":"Packagist","name":"tribalsystems/zenario","fixedVersion":"8.8.53370"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2021-27673"},{"type":"WEB","url":"https://deadsh0t.medium.com/blind-error-based-authenticated-sql-injection-on-zenario-8-8-52729-cms-d4705534df38"},{"type":"PACKAGE","url":"https://github.com/TribalSystems/Zenario"},{"type":"WEB","url":"https://github.com/TribalSystems/Zenario/releases/tag/8.8.53370"},{"type":"WEB","url":"http://packetstormsecurity.com/files/163083/Zenario-CMS-8.8.52729-SQL-Injection.html"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2024-02-16T08:17:21.867289Z"}}