{"id":"CVE-2022-23043","details":"Zenario CMS 9.2 allows an authenticated admin user to bypass the file upload restriction by creating a new 'File/MIME Types' using the '.phar' extension. Then an attacker can upload a malicious file, intercept the request and change the extension to '.phar' in order to run commands on the server.","aliases":["GHSA-6r86-2jm9-9mh4"],"modified":"2026-08-12T03:51:09.377153038Z","published":"2022-02-22T18:21:02Z","database_specific":{"cna_assigner":"Fluid Attacks","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/23xxx/CVE-2022-23043.json"},"references":[{"type":"WEB","url":"https://github.com/TribalSystems/Zenario/releases/tag/9.2.55826"},{"type":"ADVISORY","url":"https://fluidattacks.com/advisories/simone/"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/23xxx/CVE-2022-23043.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-23043"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/tribalsystems/zenario","events":[{"introduced":"0c65c8c3446059491a95edf38cb73d70321eccbc"},{"fixed":"f0682d22688d9921dc0dfd6e858900ebf2706f19"}],"database_specific":{"extracted_events":[{"introduced":"9.2"},{"last_affected":"9.2"}],"source":["CPE_STRING","REFERENCES"],"cpe":"cpe:2.3:a:tribalsystems:zenario:9.2:*:*:*:*:*:*:*"}}],"versions":["9.2"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-23043.json"}}],"schema_version":"1.9.0"}