CVE-2021-27672
PHP vulnerability analysis and mitigation

Overview

A SQL injection vulnerability was discovered in Zenario CMS version 8.8.52729, identified as CVE-2021-27672. The vulnerability exists in the admin_boxes.ajax.php file when creating a new HTML page, specifically in the 'cID' parameter. This vulnerability was discovered by Avinash R from Zacco Cyber Security Research Labs and was reported on February 5, 2021, with a fix released on February 8, 2021 in version 8.8.53370 (Medium Blog).

Technical details

The vulnerability is present in the admin interface of Zenario CMS when creating new HTML pages. The 'cID' parameter in admin_boxes.ajax.php is susceptible to SQL injection attacks. The issue can be confirmed by inserting a single quote character into the cID parameter, which triggers SQL error messages. The vulnerability allows for both blind and error-based SQL injection techniques (Medium Blog).

Impact

When exploited, this vulnerability allows authenticated administrators to potentially dump all data from the database through SQL injection attacks. The vulnerability provides access to sensitive database information through the injection of SQL commands into the 'cID' parameter (Medium Blog).

Mitigation and workarounds

The vulnerability was patched in Zenario CMS version 8.8.53370. Users should upgrade to this version or later to mitigate the risk. The fixed version is available through the official Zenario GitHub repository (Medium Blog).

Additional resources


SourceThis report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-898v-775g-777cCRITICAL9.4
  • PHPPHP
  • neuron-core/neuron-ai
NoYesDec 09, 2025
GHSA-5j8p-438x-rgg5CRITICAL9.3
  • PHPPHP
  • onelogin/php-saml
NoYesDec 09, 2025
GHSA-j8g6-5gqc-mq36HIGH8.2
  • PHPPHP
  • neuron-core/neuron-ai
NoYesDec 09, 2025
GHSA-pvcv-q3q7-266gHIGH8.1
  • PHPPHP
  • filament/filament
NoYesDec 09, 2025
GHSA-6w82-v552-wjw2HIGH7.1
  • PHPPHP
  • shopware/shopware
NoYesDec 09, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management