VYPR
High severity7.5NVD Advisory· Published Sep 23, 2019· Updated Jun 17, 2026

CVE-2019-16720

CVE-2019-16720

Description

ZZZCMS zzzphp v1.7.2 does not properly restrict file upload in plugins/ueditor/php/controller.php?upfolder=news&action=catchimage, as demonstrated by uploading a .htaccess or .php5 file.

Affected products

3
  • Zzcms/Zzzphp2 versions
    cpe:2.3:a:zzzcms:zzzphp:1.7.2:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:zzzcms:zzzphp:1.7.2:*:*:*:*:*:*:*
    • (no CPE)range: =1.7.2
  • ZZZCMS/zzzphpdescription

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.