PT-2021-23922 · Zzcms · Zzcms
Rpsateo
·
Published
2021-12-09
·
Updated
2022-07-12
·
CVE-2021-43703
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
zzcms versions less than or equal to 2019
Description:
An issue exists due to incorrect access control in zzcms, allowing direct access to the administrator console via "admin.php" after disabling JavaScript.
Recommendations:
For zzcms versions less than or equal to 2019, consider disabling access to the "admin.php" endpoint until a fix is available. As a temporary workaround, ensure JavaScript is enabled to prevent unauthorized access to the administrator console.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Zzcms