Miggo Logo

CVE-2022-23043: File upload restriction bypass in Zenario CMS

7.2

CVSS Score
3.1

Basic Information

EPSS Score
0.73463%
Published
2/25/2022
Updated
2/3/2023
KEV Status
No
Technology
TechnologyPHP

Technical Details

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Package NameEcosystemVulnerable VersionsFirst Patched Version
tribalsystems/zenariocomposer< 9.2.558269.2.55826

Vulnerability Intelligence
Miggo AIMiggo AI

Miggo AIRoot Cause Analysis:
In progress

WAF Protection Rules

WAF Rule

Z*n*rio *MS *.* *llows *n *ut**nti**t** **min us*r to *yp*ss t** *il* uplo** r*stri*tion *y *r**tin* * n*w '*il*/MIM* Typ*s' usin* t** '.p**r' *xt*nsion. T**n *n *tt**k*r **n uplo** * m*li*ious *il*, int*r**pt t** r*qu*st *n* ***n** t** *xt*nsion to

Reasoning

No *n*lysis *v*il**l*