← Back to CVE List

CVE-2022-23043

Published: 2022-02-24T15:15Z
Last Modified: 2024-11-21T06:47Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
Zenario CMS 9.2 allows an authenticated admin user to bypass the file upload restriction by creating a new 'File/MIME Types' using the '.phar' extension. Then an attacker can upload a malicious file, intercept the request and change the extension to '.phar' in order to run commands on the server. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt