Zzcms · Zzcms · CVE-2021-43703
Name of the Vulnerable Software and Affected Versions:
zzcms versions less than or equal to 2019
Description:
An issue exists due to incorrect access control in zzcms, allowing direct access to the administrator console via "admin.php" after disabling JavaScript.
Recommendations:
For zzcms versions less than or equal to 2019, consider disabling access to the "admin.php" endpoint until a fix is available. As a temporary workaround, ensure JavaScript is enabled to prevent unauthorized access to the administrator console.