vendor:
Zenar Content Management System
by:
Berk Dusunur
5.5
CVSS
MEDIUM
Cross-Site Scripting
79
CWE
Product Name: Zenar Content Management System
Affected Version From:
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
2018
Zenar Content Management System – Cross-Site Scripting
This exploit allows an attacker to inject malicious code into a website that uses the Zenar Content Management System. By sending a crafted POST request to the /zenario/ajax.php endpoint, an attacker can execute arbitrary JavaScript code on the target site.
Mitigation:
To mitigate this vulnerability, it is recommended to sanitize user input and properly encode any output that is displayed on the website.