Lucene search

K
cve[email protected]CVE-2023-45555
HistoryOct 25, 2023 - 6:17 p.m.

CVE-2023-45555

2023-10-2518:17:33
CWE-434
web.nvd.nist.gov
44
cve-2023-45555
file upload
zzzcms
remote code execution
security vulnerability

7.8 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

0.001 Low

EPSS

Percentile

35.4%

File Upload vulnerability in zzzCMS v.2.1.9 allows a remote attacker to execute arbitrary code via a crafted file to the down_url function in zzz.php file.

Affected configurations

NVD
Node
zzzcmszzzcmsMatch2.1.9
CPENameOperatorVersion
zzzcms:zzzcmszzzcmseq2.1.9

7.8 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

0.001 Low

EPSS

Percentile

35.4%

Related for CVE-2023-45555