Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2022-20177
HistoryFeb 16, 2022 - 12:00 a.m.

zzcms authorization problem vulnerability

2022-02-1600:00:00
China National Vulnerability Database
www.cnvd.org.cn
9
zzcms
china
security vulnerability
access control
authentication
cookie
bypass
attackers
cnvd

EPSS

0.001

Percentile

39.0%

ZZCMS is a content management system (CMS) from the Zzcms team in China. zzcms suffers from a security vulnerability that stems from an incorrect access control vulnerability in zzcms 8.2, which could be exploited by attackers to allow malicious users to bypass authentication by changing the username in a cookie to use any password.

EPSS

0.001

Percentile

39.0%

Related for CNVD-2022-20177