CVE-2023-50104

CRITICAL WAF: Medium
CVSS 9.8 Published: 2023-12-29
CWE-434

ZZCMS 2023 has a file upload vulnerability in 3/E_bak5.1/upload/index.php, allowing attackers to exploit this loophole to gain server privileges and execute arbitrary code.

WAF Coverage Analysis

Unrestricted File Upload Medium WAF Coverage

OWASP: A04:2021 Insecure Design

930xxx - Local File Inclusion

Affected Software

VendorProductVersion
zzcmszzcms2023

References

Back to CVE Database