Zenar Content Management System Cross-Site Scripting via ajax.php
Vulnerability Description
Zenar Content Management System contains a cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by manipulating form parameters in POST requests. Attackers can inject script tags through the current_page parameter sent to the ajax.php endpoint, which reflects unsanitized user input in the response HTML to execute arbitrary JavaScript in victim browsers.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2018-25331
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Berk Dusunur
Affected Vendor
zenar
View all reports →