Zenario CMS 9.2 allows an authenticated admin user to bypass the file upload restriction by creating a new 'File/MIME Types' using the '.phar' extension. Then an attacker can upload a malicious file, intercept the request and change the extension to '.phar' in order to run commands on the server.
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.
Link | Tags |
---|---|
https://fluidattacks.com/advisories/simone/ | patch third party advisory exploit |
https://github.com/TribalSystems/Zenario/releases/tag/9.2.55826 | patch third party advisory release notes |