PT-2025-47372 · Dzzoffice · Dzzoffice

Published

2025-11-18

·

Updated

2025-11-19

·

CVE-2025-63695

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions DzzOffice versions prior to 2.3.7
Description DzzOffice is susceptible to an arbitrary file upload issue located in the /dzz/system/ueditor/php/controller.php file. The issue resides within the controller.php component.
Recommendations Update to a version later than 2.3.7.

Exploit

Fix

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2025-63695

Affected Products

Dzzoffice