PT-2025-40780 · Seriawei · Zkeacms

Yu Bao

·

Published

2025-10-04

·

Updated

2025-10-04

·

CVE-2025-11272

CVSS v2.0

5.5

Medium

VectorAV:N/AC:L/Au:S/C:N/I:P/A:P
Name of the Vulnerable Software and Affected Versions SeriaWei ZKEACMS versions up to 4.3
Description A flaw exists in the Delete function within the src/ZKEACMS.Redirection/Controllers/UrlRedirectionController.cs file of the POST Request Handler component. This issue results in improper authorization, potentially allowing for remote exploitation. The exploit for this issue has been publicly disclosed. The vendor was informed of this disclosure but did not provide a response.
Recommendations Versions prior to 4.4 are affected. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Authorization

Incorrect Privilege Assignment

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-11272

Affected Products

Zkeacms