Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2024-06241
HistoryJan 05, 2024 - 12:00 a.m.

ZZCMS File Upload Vulnerability (CNVD-2024-06241)

2024-01-0500:00:00
China National Vulnerability Database
www.cnvd.org.cn
17
zzcms
file upload
vulnerability
china
content management system
server privileges
arbitrary code
cnvd-2024-06241

7.8 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

50.3%

ZZCMS is a content management system (CMS) by the ZZCMS team in China. A file upload vulnerability exists in ZZCMS version 2023, which stems from the lack of valid validation of uploaded files in /E_bak5.1/upload/index.php. An attacker can exploit this vulnerability to gain server privileges and execute arbitrary code.

7.8 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

50.3%

Related for CNVD-2024-06241