Metrics
Affected Vendors & Products
Wed, 23 Apr 2025 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Zzcms
Zzcms zzcms |
|
| CPEs | cpe:2.3:a:zzcms:zzcms:2025:*:*:*:*:*:*:* | |
| Vendors & Products |
Zzcms
Zzcms zzcms |
Tue, 04 Mar 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 04 Mar 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability, which was classified as problematic, has been found in ZZCMS 2025. This issue affects some unknown processing of the file /3/ucenter_api/code/register_nodb.php of the component URL Handler. The manipulation of the argument $_SERVER['PHP_SELF'] leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. | |
| Title | ZZCMS URL register_nodb.php cross site scripting | |
| Weaknesses | CWE-79 CWE-94 |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published: 2025-03-04T19:00:07.588Z
Updated: 2025-03-04T19:37:04.767Z
Reserved: 2025-03-04T14:09:51.585Z
Link: CVE-2025-1949
Updated: 2025-03-04T19:36:57.380Z
Status : Analyzed
Published: 2025-03-04T19:15:37.943
Modified: 2025-04-23T15:00:45.713
Link: CVE-2025-1949
No data.
ReportizFlow