PT-2025-32535 · Unknown · Zlt2000 Microservices-Platform

Zast.Ai

·

Published

2025-08-11

·

Updated

2025-09-16

·

CVE-2025-8841

CVSS v3.1

6.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions: zlt2000 microservices-platform versions through 6.0.0
Description: A vulnerability exists in the Upload function located in zlt-business/file-center/src/main/java/com/central/file/controller/FileController.java. This manipulation allows for unrestricted file uploads and can be exploited remotely. The exploit has been publicly disclosed and may be in use.
Recommendations: Versions prior to 6.0.0 are affected. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Access Control

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2025-8841

Affected Products

Zlt2000 Microservices-Platform