Executive brief
Zenar Content Management System (Zenario), a platform used for building and managing websites, contains a security flaw that allows attackers to inject malicious scripts into the site. By sending a specially crafted web request to the system's AJAX endpoint, an attacker can execute arbitrary JavaScript in the browsers of other users who visit the site. This could lead to unauthorized actions being performed on behalf of users, theft of session cookies, or the defacement of web pages.
Technical details
A reflected cross-site scripting (XSS) vulnerability exists in Zenar Content Management System (Zenario) versions 7.0 and earlier. The vulnerability is located in the 'ajax.php' endpoint, specifically within the 'current_page' POST parameter when the 'method_call' is set to 'refreshPlugin'. The application fails to properly sanitize this parameter before reflecting it back in the HTML response within a fieldset ID attribute. An unauthenticated remote attacker can exploit this by enticing a user to submit a crafted request, allowing for the execution of arbitrary JavaScript in the context of the victim's session. This can be used to bypass CSRF protections, steal session tokens, or perform unauthorized actions.
Affected products
- Tribal Systems Zenar Content Management System (Zenario) <= 7.0
Timeline
- 2018-05-20: disclosed: Vulnerability discovered and PoC created by Berk Dusunur
- 2018-05-21: other: Exploit published on Exploit-DB
- 2026-05-17: advisory: CVE-2018-25331 published to NVD