Описание
A flaw has been found in ZZCMS 2025. Affected by this vulnerability is an unknown functionality of the file /reg/user_save.php of the component User Data Storage Module. This manipulation causes cleartext storage in a file or on disk. Remote exploitation of the attack is possible. The exploit has been published and may be used.
Ссылки
- Third Party Advisory
- Permissions RequiredVDB Entry
- Third Party AdvisoryVDB Entry
- Third Party AdvisoryVDB Entry
- Third Party Advisory
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:zzcms:zzcms:2025:*:*:*:*:*:*:*
EPSS
Процентиль: 2%
0.00014
Низкий
2.7 Low
CVSS3
3.3 Low
CVSS2
Дефекты
CWE-312
Связанные уязвимости
CVSS3: 2.7
github
около 2 месяцев назад
A flaw has been found in ZZCMS 2025. Affected by this vulnerability is an unknown functionality of the file /reg/user_save.php of the component User Data Storage Module. This manipulation causes cleartext storage in a file or on disk. Remote exploitation of the attack is possible. The exploit has been published and may be used.
EPSS
Процентиль: 2%
0.00014
Низкий
2.7 Low
CVSS3
3.3 Low
CVSS2
Дефекты
CWE-312