PT-2021-23922 · Zzcms · Zzcms

Rpsateo

·

Published

2021-12-09

·

Updated

2022-07-12

·

CVE-2021-43703

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: zzcms versions less than or equal to 2019
Description: An issue exists due to incorrect access control in zzcms, allowing direct access to the administrator console via "admin.php" after disabling JavaScript.
Recommendations: For zzcms versions less than or equal to 2019, consider disabling access to the "admin.php" endpoint until a fix is available. As a temporary workaround, ensure JavaScript is enabled to prevent unauthorized access to the administrator console.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2021-43703

Affected Products

Zzcms