PT-2026-28717 · Unknown · Z-9527 Admin

·

CVE-2026-4999

·

Publicado

2026-03-28

·

Atualizado

2026-03-29

CVSS v2.0

6.5

Média

VetorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions z-9527 admin versions prior to 72aaf2dd05cf4ec2e98f390668b41e128eec5ad2
Description A security issue has been identified in z-9527 admin. The issue resides within the uploadFile function located in the /server/utils/upload.js file, specifically within the isImg Check component. Manipulation of the fileType argument can lead to a path traversal condition. Remote exploitation is possible. The exploit has been publicly disclosed.
Recommendations Update z-9527 admin to version 72aaf2dd05cf4ec2e98f390668b41e128eec5ad2 or later. As a temporary workaround, restrict access to the uploadFile function in the /server/utils/upload.js file. Avoid using the fileType parameter in the uploadFile function until the issue is resolved.

Exploit

Correção

Path traversal

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-4999

Produtos afetados

Z-9527 Admin