PT-2025-54429 · Zwiicms · Zwiicms

Matías Schiappacasse

·

Published

2025-12-31

·

Updated

2026-02-02

·

CVE-2025-34467

CVSS v4.0

5.3

Medium

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions ZwiiCMS versions prior to 13.7.00
Description The software contains a denial-of-service issue in several administrative areas because of incorrect authorization checks and problems with how resources are handled. A user with limited access can request an administrative page, which should result in a "404 Not Found" error. However, the application incorrectly obtains and links a temporary lock on the requested resource to the attacker's session before checking if the user is authorized. This lock prevents other users, including administrators, from accessing the affected features until the attacker leaves the page or their session ends. The affected administrative endpoints include multiple locations.
Recommendations Update to version 13.7.00 or later.

Fix

DoS

Incorrect Authorization

Improper Locking

Weakness Enumeration

Related Identifiers

CVE-2025-34467

Affected Products

Zwiicms