PT-2025-38659 · Unknown · Seriawei Zkeacms
Yu_Bao
·
Published
2025-09-21
·
Updated
2025-10-14
·
CVE-2025-10764
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
SeriaWei ZKEACMS versions prior to 4.4
Description
A vulnerability exists in SeriaWei ZKEACMS up to version 4.3. The issue affects the
Edit function within the src/ZKEACMS.EventAction/Controllers/PendingTaskController.cs file of the Event Action System component. Manipulation of the Data argument can lead to server-side request forgery. The attack can be performed remotely. The exploit is publicly available.Recommendations
Update SeriaWei ZKEACMS to version 4.4 or later.
As a temporary workaround, restrict access to the
Edit function within the src/ZKEACMS.EventAction/Controllers/PendingTaskController.cs file.
Avoid using the Data parameter in the Edit function until the issue is resolved.Exploit
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Seriawei Zkeacms