Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-65897

Опубликовано: 05 дек. 2025
Источник: nvd
CVSS3: 8.8
EPSS Низкий

Описание

zdh_web is a data collection, processing, monitoring, scheduling, and management platform. In zdh_web thru 5.6.17, insufficient validation of file upload paths in the application allows an authenticated user to write arbitrary files to the server file system, potentially overwriting existing files and leading to privilege escalation or remote code execution.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:zhaoyachao:zdh_web:*:*:*:*:*:*:*:*
Версия до 5.6.17 (включая)

EPSS

Процентиль: 60%
0.00402
Низкий

8.8 High

CVSS3

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 8.8
github
2 месяца назад

zdh_web is a data collection, processing, monitoring, scheduling, and management platform. In zdh_web thru 5.6.17, insufficient validation of file upload paths in the application allows an authenticated user to write arbitrary files to the server file system, potentially overwriting existing files and leading to privilege escalation or remote code execution.

EPSS

Процентиль: 60%
0.00402
Низкий

8.8 High

CVSS3

Дефекты

CWE-22