ZeroHour

CVE-2021-37144

PoC
CVSS 3.1
9.1 critical
EPSS
1%p68
Published
()
Modified
Description

CSZ CMS 1.2.9 is vulnerable to Arbitrary File Deletion. This occurs in PHP when the unlink() function is called and user input might affect portions of or the whole affected parameter, which represents the path of the file to remove, without sufficient sanitization.

Vendors
cszcms
Products
csz cms
Weakness
CWE-706
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H

In the news

No ingested article mentions this CVE yet.