GHSA-q3m7-9pg6-jjh6MediumCVSS 6.1
Zenar Content Management System contains a cross-site scripting vulnerability that allows...
🔗 CVE IDs covered (1)
📋 Description
Zenar Content Management System contains a cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by manipulating form parameters in POST requests. Attackers can inject script tags through the current_page parameter sent to the ajax.php endpoint, which reflects unsanitized user input in the response HTML to execute arbitrary JavaScript in victim browsers.