Zenar Content Management System contains a cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by manipulating form parameters in POST requests. Attackers can inject script tags through the current_page parameter sent to the ajax.php endpoint, which reflects unsanitized user input in the response HTML to execute arbitrary JavaScript in victim browsers.
Metrics
Affected Vendors & Products
References
History
Sun, 17 May 2026 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Zenar
Zenar zenar Content Management System |
|
| Vendors & Products |
Zenar
Zenar zenar Content Management System |
Sun, 17 May 2026 12:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Zenar Content Management System contains a cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by manipulating form parameters in POST requests. Attackers can inject script tags through the current_page parameter sent to the ajax.php endpoint, which reflects unsanitized user input in the response HTML to execute arbitrary JavaScript in victim browsers. | |
| Title | Zenar Content Management System Cross-Site Scripting via ajax.php | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published: 2026-05-17T12:11:36.116Z
Updated: 2026-05-17T12:11:36.116Z
Reserved: 2026-05-17T11:47:21.491Z
Link: CVE-2018-25331
No data.
Status : Received
Published: 2026-05-17T13:16:44.710
Modified: 2026-05-17T13:16:44.710
Link: CVE-2018-25331
No data.