Vendor CVEs
Zzcms
All CVEs
132 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-40281 | Hig | 0.57 | 8.8 | 0.01 | Dec 9, 2021 | An SQL Injection vulnerability exists in zzcms 8.2, 8.3, 2020, and 2021 in dl/dl_print.php when registering ordinary users. | ||
| CVE-2020-23630 | Hig | 0.57 | 8.8 | 0.01 | Jan 11, 2021 | A blind SQL injection vulnerability exists in zzcms ver201910 based on time (cookie injection). | ||
| CVE-2018-17415 | Hig | 0.57 | 8.8 | 0.01 | Mar 7, 2019 | zzcms V8.3 has a SQL injection in /user/zs_elite.php via the id parameter. | ||
| CVE-2018-17414 | Hig | 0.57 | 8.8 | 0.01 | Mar 7, 2019 | zzcms v8.3 has a SQL injection in /user/jobmanage.php via the bigclass parameter. | ||
| CVE-2019-9182 | Hig | 0.57 | 8.8 | 0.01 | Feb 26, 2019 | There is a CSRF in ZZZCMS zzzphp V1.6.1 via a /admin015/save.php?act=editfile request. It allows PHP code injection by providing a filename in the file parameter, and providing file content in the filetext parameter. | ||
| CVE-2018-14963 | Hig | 0.57 | 8.8 | 0.01 | Aug 6, 2018 | zzcms 8.3 has CSRF via the admin/adminadd.php?action=add URI. | ||
| CVE-2019-9041 | Hig | 0.52 | 7.2 | 0.31 | Feb 23, 2019 | An issue was discovered in ZZZCMS zzzphp V1.6.1. In the inc/zzz_template.php file, the parserIfLabel() function's filtering is not strict, resulting in PHP code execution, as demonstrated by the if:assert substring. | ||
| CVE-2023-45555 | Hig | 0.51 | 7.8 | 0.01 | Oct 25, 2023 | File Upload vulnerability in zzzCMS v.2.1.9 allows a remote attacker to execute arbitrary code via a crafted file to the down_url function in zzz.php file. | ||
| CVE-2021-45347 | Hig | 0.49 | 7.5 | 0.01 | Feb 14, 2022 | An Incorrect Access Control vulnerability exists in zzcms 8.2, which lets a malicious user bypass authentication by changing the user name in the cookie to use any password. | ||
| CVE-2020-19961 | Hig | 0.49 | 7.5 | 0.02 | Oct 14, 2021 | A SQL injection vulnerability has been discovered in zz cms version 2019 which allows attackers to retrieve sensitive data via the component subzs.php. | ||
| CVE-2020-19960 | Hig | 0.49 | 7.5 | 0.02 | Oct 14, 2021 | A SQL injection vulnerability has been discovered in zz cms version 2019 which allows attackers to retrieve sensitive data via the dlid parameter in the /dl/dl_sendsms.php page cookie. | ||
| CVE-2020-19959 | Hig | 0.49 | 7.5 | 0.02 | Oct 14, 2021 | A SQL injection vulnerability has been discovered in zz cms version 2019 which allows attackers to retrieve sensitive data via the dlid parameter in the /dl/dl_sendmail.php page cookie. | ||
| CVE-2020-19957 | Hig | 0.49 | 7.5 | 0.02 | Oct 14, 2021 | A SQL injection vulnerability has been discovered in zz cms version 2019 which allows attackers to retrieve sensitive data via the id parameter on the /dl/dl_print.php page. | ||
| CVE-2020-21342 | Hig | 0.49 | 7.5 | 0.01 | May 13, 2021 | Insecure permissions issue in zzcms 201910 via the reset any user password in /one/getpassword.php. | ||
| CVE-2019-16720 | Hig | 0.49 | 7.5 | 0.01 | Sep 23, 2019 | ZZZCMS zzzphp v1.7.2 does not properly restrict file upload in plugins/ueditor/php/controller.php?upfolder=news&action=catchimage, as demonstrated by uploading a .htaccess or .php5 file. | ||
| CVE-2019-8411 | Hig | 0.49 | 7.5 | 0.03 | Feb 17, 2019 | admin/dl_data.php in zzcms 2018 (2018-10-19) allows remote attackers to delete arbitrary files via action=del&filename=../ directory traversal. | ||
| CVE-2018-20127 | Hig | 0.49 | 7.5 | 0.01 | Dec 13, 2018 | An issue was discovered in zzzphp cms 1.5.8. del_file in /admin/save.php allows remote attackers to delete arbitrary files via a mixed-case extension and an extra '.' character, because (for example) "php" is blocked but path=F:/1.phP. succeeds. | ||
| CVE-2018-16344 | Hig | 0.49 | 7.5 | 0.02 | Sep 2, 2018 | An issue was discovered in zzcms 8.3. It allows remote attackers to delete arbitrary files via directory traversal sequences in the flv parameter. This can be leveraged for database access by deleting install.lock. | ||
| CVE-2018-13056 | Hig | 0.49 | 7.5 | 0.01 | Jul 2, 2018 | An issue was discovered on zzcms 8.3. There is a vulnerability at /user/del.php that can delete any file by placing its relative path into the zzcms_main table and then making an img add request. This can be leveraged for database access by deleting install.lock. | ||
| CVE-2018-9331 | Hig | 0.49 | 7.5 | 0.03 | Apr 7, 2018 | An issue was discovered in zzcms 8.2. user/adv.php allows remote attackers to delete arbitrary files via directory traversal sequences in the oldimg parameter. This can be leveraged for database access by deleting install.lock. | ||
| CVE-2018-8969 | Hig | 0.49 | 7.5 | 0.03 | Mar 24, 2018 | An issue was discovered in zzcms 8.2. user/licence_save.php allows remote attackers to delete arbitrary files via directory traversal sequences in the oldimg parameter in an action=modify request. This can be leveraged for database access by deleting install.lock. | ||
| CVE-2018-8968 | Hig | 0.49 | 7.5 | 0.03 | Mar 24, 2018 | An issue was discovered in zzcms 8.2. user/manage.php allows remote attackers to delete arbitrary files via directory traversal sequences in the oldimg or oldflv parameter in an action=modify request. This can be leveraged for database access by deleting install.lock. | ||
| CVE-2018-8966 | Hig | 0.49 | 7.5 | 0.02 | Mar 24, 2018 | An issue was discovered in zzcms 8.2. It allows PHP code injection via the siteurl parameter to install/index.php, as demonstrated by injecting a phpinfo() call into /inc/config.php. | ||
| CVE-2018-8965 | Hig | 0.49 | 7.5 | 0.03 | Mar 24, 2018 | An issue was discovered in zzcms 8.2. user/ppsave.php allows remote attackers to delete arbitrary files via directory traversal sequences in the oldimg parameter in an action=modify request. This can be leveraged for database access by deleting install.lock. | ||
| CVE-2025-0565 | Hig | 0.48 | 7.3 | 0.01 | Jan 19, 2025 | A vulnerability was found in ZZCMS 2023. It has been rated as critical. Affected by this issue is some unknown functionality of the file /index.php. The manipulation of the argument id leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to… | ||
| CVE-2024-7927 | Hig | 0.48 | 7.3 | 0.01 | Aug 19, 2024 | A vulnerability classified as critical was found in ZZCMS 2023. Affected by this vulnerability is an unknown functionality of the file /admin/class.php?dowhat=modifyclass. The manipulation of the argument skin[] leads to path traversal. The attack can be launched remotely. The… | ||
| CVE-2024-7926 | Hig | 0.48 | 7.3 | 0.01 | Aug 19, 2024 | A vulnerability classified as critical has been found in ZZCMS 2023. Affected is an unknown function of the file /admin/about_edit.php?action=modify. The manipulation of the argument skin leads to path traversal. It is possible to launch the attack remotely. The exploit has been… | ||
| CVE-2022-40447 | Hig | 0.47 | 7.2 | 0.01 | Sep 22, 2022 | ZZCMS 2022 was discovered to contain a SQL injection vulnerability via the keyword parameter at /admin/baojia_list.php. | ||
| CVE-2022-40446 | Hig | 0.47 | 7.2 | 0.01 | Sep 22, 2022 | ZZCMS 2022 was discovered to contain a SQL injection vulnerability via the component /admin/sendmailto.php?tomail=&groupid=. | ||
| CVE-2019-12359 | Hig | 0.47 | 7.2 | 0.01 | Jun 17, 2022 | An issue was discovered in zzcms 2019. There is a SQL injection Vulnerability in /admin/ztliuyan_sendmail.php (when the attacker has admin authority) via the id parameter. | ||
| CVE-2019-12357 | Hig | 0.47 | 7.2 | 0.01 | Jun 17, 2022 | An issue was discovered in zzcms 2019. There is a SQL injection Vulnerability in /admin/deluser.php (when the attacker has admin authority) via the id parameter. | ||
| CVE-2019-12354 | Hig | 0.47 | 7.2 | 0.01 | Jun 17, 2022 | An issue was discovered in zzcms 2019. There is a SQL injection Vulnerability in /admin/showbad.php (when the attacker has admin authority) via the id parameter. | ||
| CVE-2019-12353 | Hig | 0.47 | 7.2 | 0.01 | Jun 17, 2022 | An issue was discovered in zzcms 2019. There is a SQL injection Vulnerability in /admin/dl_sendmail.php (when the attacker has admin authority) via the id parameter. | ||
| CVE-2021-46436 | Hig | 0.47 | 7.2 | 0.01 | Apr 8, 2022 | An issue was discovered in ZZCMS 2021. There is a SQL injection vulnerability in ad_manage.php. | ||
| CVE-2021-40280 | Hig | 0.47 | 7.2 | 0.01 | Dec 9, 2021 | An SQL Injection vulnerablitly exits in zzcms 8.2, 8.3, 2020, and 2021 via the id parameter in admin/dl_sendmail.php. | ||
| CVE-2021-40279 | Hig | 0.47 | 7.2 | 0.01 | Dec 9, 2021 | An SQL Injection vulnerability exists in zzcms 8.2, 8.3, 2020, and 2021 via the id parameter in admin/bad.php. | ||
| CVE-2020-19822 | Hig | 0.47 | 7.2 | 0.03 | Aug 26, 2021 | A remote code execution (RCE) vulnerability in template_user.php of ZZCMS version 2018 allows attackers to execute arbitrary PHP code via the "ml" and "title" parameters. | ||
| CVE-2018-17416 | Hig | 0.47 | 7.2 | 0.01 | Mar 7, 2019 | A SQL injection vulnerability exists in zzcms v8.3 via the /admin/adclass.php bigclassid parameter. | ||
| CVE-2018-18790 | Hig | 0.47 | 7.2 | 0.01 | Oct 29, 2018 | An issue was discovered in zzcms 8.3. SQL Injection exists in admin/special_add.php via a zxbigclassid cookie. (This needs an admin user login.) | ||
| CVE-2018-18788 | Hig | 0.47 | 7.2 | 0.01 | Oct 29, 2018 | An issue was discovered in zzcms 8.3. SQL Injection exists in admin/classmanage.php via the tablename parameter. (This needs an admin user login.) | ||
| CVE-2018-18784 | Hig | 0.47 | 7.2 | 0.01 | Oct 29, 2018 | An issue was discovered in zzcms 8.3. SQL Injection exists in admin/tagmanage.php via the tabletag parameter. (This needs an admin user login.) | ||
| CVE-2018-17798 | Med | 0.42 | 6.5 | 0.01 | Sep 30, 2018 | An issue was discovered in zzcms 8.3. user/ztconfig.php allows remote attackers to delete arbitrary files via an absolute pathname in the oldimg parameter in an action=modify request. This can be leveraged for database access by deleting install.lock. | ||
| CVE-2018-17797 | Med | 0.42 | 6.5 | 0.01 | Sep 30, 2018 | An issue was discovered in zzcms 8.3. user/zssave.php allows remote attackers to delete arbitrary files via directory traversal sequences in the oldimg parameter in an action=modify request. This can be leveraged for database access by deleting install.lock. | ||
| CVE-2025-13171 | Med | 0.41 | 6.3 | 0.00 | Nov 14, 2025 | A vulnerability was identified in ZZCMS 2023. This impacts an unknown function of the file /admin/wangkan_list.php. Such manipulation of the argument keyword leads to sql injection. The attack can be launched remotely. The exploit is publicly available and might be used. | ||
| CVE-2024-10293 | Med | 0.41 | 6.3 | 0.01 | Oct 23, 2024 | A vulnerability was found in ZZCMS 2023. It has been classified as critical. Affected is the function Ebak_SetGotoPak of the file 3/Ebbak5.1/upload/class/functions.php. The manipulation of the argument file leads to unrestricted upload. It is possible to launch the attack… | ||
| CVE-2024-10292 | Med | 0.41 | 6.3 | 0.01 | Oct 23, 2024 | A vulnerability was found in ZZCMS 2023 and classified as critical. This issue affects some unknown processing of the file 3/Ebak5.1/upload/ChangeTable.php. The manipulation of the argument savefilename leads to unrestricted upload. The attack may be initiated remotely. The… | ||
| CVE-2024-10291 | Med | 0.41 | 6.3 | 0.00 | Oct 23, 2024 | A vulnerability has been found in ZZCMS 2023 and classified as critical. This vulnerability affects the function Ebak_DoExecSQL/Ebak_DotranExecutSQL of the file 3/Ebak5.1/upload/phome.php. The manipulation of the argument phome leads to sql injection. The attack can be initiated… | ||
| CVE-2023-5263 | Med | 0.41 | 6.3 | 0.01 | Sep 29, 2023 | A vulnerability was found in ZZZCMS 2.1.7 and classified as critical. Affected by this issue is the function restore of the file /admin/save.php of the component Database Backup File Handler. The manipulation leads to permission issues. The attack may be launched remotely. The… | ||
| CVE-2024-44820 | Med | 0.40 | 6.1 | 0.00 | Sep 4, 2024 | A sensitive information disclosure vulnerability exists in ZZCMS v.2023 and before within the eginfo.php file located at /3/E_bak5.1/upload/. When accessed with the query parameter phome=ShowPHPInfo, the application executes the phpinfo() function, which exposes detailed… | ||
| CVE-2024-44819 | Med | 0.40 | 6.1 | 0.00 | Sep 4, 2024 | Cross Site Scripting vulnerability in ZZCMS v.2023 and before allows a remote attacker to obtain sensitive information via a crafted script to the pagename parameter of the admin/del.php component. |
- risk 0.57cvss 8.8epss 0.01
An SQL Injection vulnerability exists in zzcms 8.2, 8.3, 2020, and 2021 in dl/dl_print.php when registering ordinary users.
- risk 0.57cvss 8.8epss 0.01
A blind SQL injection vulnerability exists in zzcms ver201910 based on time (cookie injection).
- risk 0.57cvss 8.8epss 0.01
zzcms V8.3 has a SQL injection in /user/zs_elite.php via the id parameter.
- risk 0.57cvss 8.8epss 0.01
zzcms v8.3 has a SQL injection in /user/jobmanage.php via the bigclass parameter.
- risk 0.57cvss 8.8epss 0.01
There is a CSRF in ZZZCMS zzzphp V1.6.1 via a /admin015/save.php?act=editfile request. It allows PHP code injection by providing a filename in the file parameter, and providing file content in the filetext parameter.
- risk 0.57cvss 8.8epss 0.01
zzcms 8.3 has CSRF via the admin/adminadd.php?action=add URI.
- risk 0.52cvss 7.2epss 0.31
An issue was discovered in ZZZCMS zzzphp V1.6.1. In the inc/zzz_template.php file, the parserIfLabel() function's filtering is not strict, resulting in PHP code execution, as demonstrated by the if:assert substring.
- risk 0.51cvss 7.8epss 0.01
File Upload vulnerability in zzzCMS v.2.1.9 allows a remote attacker to execute arbitrary code via a crafted file to the down_url function in zzz.php file.
- risk 0.49cvss 7.5epss 0.01
An Incorrect Access Control vulnerability exists in zzcms 8.2, which lets a malicious user bypass authentication by changing the user name in the cookie to use any password.
- risk 0.49cvss 7.5epss 0.02
A SQL injection vulnerability has been discovered in zz cms version 2019 which allows attackers to retrieve sensitive data via the component subzs.php.
- risk 0.49cvss 7.5epss 0.02
A SQL injection vulnerability has been discovered in zz cms version 2019 which allows attackers to retrieve sensitive data via the dlid parameter in the /dl/dl_sendsms.php page cookie.
- risk 0.49cvss 7.5epss 0.02
A SQL injection vulnerability has been discovered in zz cms version 2019 which allows attackers to retrieve sensitive data via the dlid parameter in the /dl/dl_sendmail.php page cookie.
- risk 0.49cvss 7.5epss 0.02
A SQL injection vulnerability has been discovered in zz cms version 2019 which allows attackers to retrieve sensitive data via the id parameter on the /dl/dl_print.php page.
- risk 0.49cvss 7.5epss 0.01
Insecure permissions issue in zzcms 201910 via the reset any user password in /one/getpassword.php.
- risk 0.49cvss 7.5epss 0.01
ZZZCMS zzzphp v1.7.2 does not properly restrict file upload in plugins/ueditor/php/controller.php?upfolder=news&action=catchimage, as demonstrated by uploading a .htaccess or .php5 file.
- risk 0.49cvss 7.5epss 0.03
admin/dl_data.php in zzcms 2018 (2018-10-19) allows remote attackers to delete arbitrary files via action=del&filename=../ directory traversal.
- risk 0.49cvss 7.5epss 0.01
An issue was discovered in zzzphp cms 1.5.8. del_file in /admin/save.php allows remote attackers to delete arbitrary files via a mixed-case extension and an extra '.' character, because (for example) "php" is blocked but path=F:/1.phP. succeeds.
- risk 0.49cvss 7.5epss 0.02
An issue was discovered in zzcms 8.3. It allows remote attackers to delete arbitrary files via directory traversal sequences in the flv parameter. This can be leveraged for database access by deleting install.lock.
- risk 0.49cvss 7.5epss 0.01
An issue was discovered on zzcms 8.3. There is a vulnerability at /user/del.php that can delete any file by placing its relative path into the zzcms_main table and then making an img add request. This can be leveraged for database access by deleting install.lock.
- risk 0.49cvss 7.5epss 0.03
An issue was discovered in zzcms 8.2. user/adv.php allows remote attackers to delete arbitrary files via directory traversal sequences in the oldimg parameter. This can be leveraged for database access by deleting install.lock.
- risk 0.49cvss 7.5epss 0.03
An issue was discovered in zzcms 8.2. user/licence_save.php allows remote attackers to delete arbitrary files via directory traversal sequences in the oldimg parameter in an action=modify request. This can be leveraged for database access by deleting install.lock.
- risk 0.49cvss 7.5epss 0.03
An issue was discovered in zzcms 8.2. user/manage.php allows remote attackers to delete arbitrary files via directory traversal sequences in the oldimg or oldflv parameter in an action=modify request. This can be leveraged for database access by deleting install.lock.
- risk 0.49cvss 7.5epss 0.02
An issue was discovered in zzcms 8.2. It allows PHP code injection via the siteurl parameter to install/index.php, as demonstrated by injecting a phpinfo() call into /inc/config.php.
- risk 0.49cvss 7.5epss 0.03
An issue was discovered in zzcms 8.2. user/ppsave.php allows remote attackers to delete arbitrary files via directory traversal sequences in the oldimg parameter in an action=modify request. This can be leveraged for database access by deleting install.lock.
- risk 0.48cvss 7.3epss 0.01
A vulnerability was found in ZZCMS 2023. It has been rated as critical. Affected by this issue is some unknown functionality of the file /index.php. The manipulation of the argument id leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to…
- risk 0.48cvss 7.3epss 0.01
A vulnerability classified as critical was found in ZZCMS 2023. Affected by this vulnerability is an unknown functionality of the file /admin/class.php?dowhat=modifyclass. The manipulation of the argument skin[] leads to path traversal. The attack can be launched remotely. The…
- risk 0.48cvss 7.3epss 0.01
A vulnerability classified as critical has been found in ZZCMS 2023. Affected is an unknown function of the file /admin/about_edit.php?action=modify. The manipulation of the argument skin leads to path traversal. It is possible to launch the attack remotely. The exploit has been…
- risk 0.47cvss 7.2epss 0.01
ZZCMS 2022 was discovered to contain a SQL injection vulnerability via the keyword parameter at /admin/baojia_list.php.
- risk 0.47cvss 7.2epss 0.01
ZZCMS 2022 was discovered to contain a SQL injection vulnerability via the component /admin/sendmailto.php?tomail=&groupid=.
- risk 0.47cvss 7.2epss 0.01
An issue was discovered in zzcms 2019. There is a SQL injection Vulnerability in /admin/ztliuyan_sendmail.php (when the attacker has admin authority) via the id parameter.
- risk 0.47cvss 7.2epss 0.01
An issue was discovered in zzcms 2019. There is a SQL injection Vulnerability in /admin/deluser.php (when the attacker has admin authority) via the id parameter.
- risk 0.47cvss 7.2epss 0.01
An issue was discovered in zzcms 2019. There is a SQL injection Vulnerability in /admin/showbad.php (when the attacker has admin authority) via the id parameter.
- risk 0.47cvss 7.2epss 0.01
An issue was discovered in zzcms 2019. There is a SQL injection Vulnerability in /admin/dl_sendmail.php (when the attacker has admin authority) via the id parameter.
- risk 0.47cvss 7.2epss 0.01
An issue was discovered in ZZCMS 2021. There is a SQL injection vulnerability in ad_manage.php.
- risk 0.47cvss 7.2epss 0.01
An SQL Injection vulnerablitly exits in zzcms 8.2, 8.3, 2020, and 2021 via the id parameter in admin/dl_sendmail.php.
- risk 0.47cvss 7.2epss 0.01
An SQL Injection vulnerability exists in zzcms 8.2, 8.3, 2020, and 2021 via the id parameter in admin/bad.php.
- risk 0.47cvss 7.2epss 0.03
A remote code execution (RCE) vulnerability in template_user.php of ZZCMS version 2018 allows attackers to execute arbitrary PHP code via the "ml" and "title" parameters.
- risk 0.47cvss 7.2epss 0.01
A SQL injection vulnerability exists in zzcms v8.3 via the /admin/adclass.php bigclassid parameter.
- risk 0.47cvss 7.2epss 0.01
An issue was discovered in zzcms 8.3. SQL Injection exists in admin/special_add.php via a zxbigclassid cookie. (This needs an admin user login.)
- risk 0.47cvss 7.2epss 0.01
An issue was discovered in zzcms 8.3. SQL Injection exists in admin/classmanage.php via the tablename parameter. (This needs an admin user login.)
- risk 0.47cvss 7.2epss 0.01
An issue was discovered in zzcms 8.3. SQL Injection exists in admin/tagmanage.php via the tabletag parameter. (This needs an admin user login.)
- risk 0.42cvss 6.5epss 0.01
An issue was discovered in zzcms 8.3. user/ztconfig.php allows remote attackers to delete arbitrary files via an absolute pathname in the oldimg parameter in an action=modify request. This can be leveraged for database access by deleting install.lock.
- risk 0.42cvss 6.5epss 0.01
An issue was discovered in zzcms 8.3. user/zssave.php allows remote attackers to delete arbitrary files via directory traversal sequences in the oldimg parameter in an action=modify request. This can be leveraged for database access by deleting install.lock.
- risk 0.41cvss 6.3epss 0.00
A vulnerability was identified in ZZCMS 2023. This impacts an unknown function of the file /admin/wangkan_list.php. Such manipulation of the argument keyword leads to sql injection. The attack can be launched remotely. The exploit is publicly available and might be used.
- risk 0.41cvss 6.3epss 0.01
A vulnerability was found in ZZCMS 2023. It has been classified as critical. Affected is the function Ebak_SetGotoPak of the file 3/Ebbak5.1/upload/class/functions.php. The manipulation of the argument file leads to unrestricted upload. It is possible to launch the attack…
- risk 0.41cvss 6.3epss 0.01
A vulnerability was found in ZZCMS 2023 and classified as critical. This issue affects some unknown processing of the file 3/Ebak5.1/upload/ChangeTable.php. The manipulation of the argument savefilename leads to unrestricted upload. The attack may be initiated remotely. The…
- risk 0.41cvss 6.3epss 0.00
A vulnerability has been found in ZZCMS 2023 and classified as critical. This vulnerability affects the function Ebak_DoExecSQL/Ebak_DotranExecutSQL of the file 3/Ebak5.1/upload/phome.php. The manipulation of the argument phome leads to sql injection. The attack can be initiated…
- risk 0.41cvss 6.3epss 0.01
A vulnerability was found in ZZZCMS 2.1.7 and classified as critical. Affected by this issue is the function restore of the file /admin/save.php of the component Database Backup File Handler. The manipulation leads to permission issues. The attack may be launched remotely. The…
- risk 0.40cvss 6.1epss 0.00
A sensitive information disclosure vulnerability exists in ZZCMS v.2023 and before within the eginfo.php file located at /3/E_bak5.1/upload/. When accessed with the query parameter phome=ShowPHPInfo, the application executes the phpinfo() function, which exposes detailed…
- risk 0.40cvss 6.1epss 0.00
Cross Site Scripting vulnerability in ZZCMS v.2023 and before allows a remote attacker to obtain sensitive information via a crafted script to the pagename parameter of the admin/del.php component.
Page 2 of 3