First published: Sat May 04 2024(Updated: )
Zenario before 9.5.60437 uses Twig filters insecurely in the Twig Snippet plugin, and in the site-wide HEAD and BODY elements, enabling code execution by a designer or an administrator.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
composer/tribalsystems/zenario | <9.5.60437 | 9.5.60437 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-34461 is classified as a high-severity vulnerability due to its potential for code execution.
To fix CVE-2024-34461, upgrade Zenario to version 9.5.60437 or later.
CVE-2024-34461 affects all versions of Zenario prior to 9.5.60437.
CVE-2024-34461 can be exploited by malicious administrators or designers to execute arbitrary code.
CVE-2024-34461 exists in the Twig Snippet plugin and the site-wide HEAD and BODY elements.