ZeroHour

CVE-2025-63608

PoC
CVSS 3.1
5.4 medium
EPSS
<1%p10
Published
()
Modified
Description

A SQL injection vulnerability exists in CSZ-CMS <=1.3.0 in the Form Builder view functionality. The vulnerability is located in the field parameter of the form viewing feature, allowing authenticated administrators to execute arbitrary SQL queries.

Vendors
cszcms
Products
csz cms
Weakness
CWE-89
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.