PT-2025-26832 · Unknown · Zoomsounds

Ganj

·

Published

2025-06-25

·

Updated

2025-06-25

·

CVE-2021-4457

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions: ZoomSounds plugin versions prior to 6.05
Description: The issue allows unauthenticated users to upload an arbitrary file anywhere on the web server due to a vulnerable PHP file.
Recommendations: For versions prior to 6.05, update to version 6.05 or later to resolve the issue.

Exploit

Fix

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2021-4457

Affected Products

Zoomsounds