PT-2021-10414 · Zzcms · Zzcms

CVE-2020-19822

·

Published

2021-08-26

·

Updated

2022-10-26

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: ZZCMS version 2018
Description: A remote code execution issue in the template user.php file allows attackers to execute arbitrary PHP code. This is achieved via the ml and title parameters.
Recommendations: For ZZCMS version 2018, consider restricting access to the template user.php file until a patch is available. As a temporary workaround, avoid using the ml and title parameters in the affected template.

Exploit

Fix

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-19822

Affected Products

Zzcms