First published: Sat Apr 07 2018(Updated: )
An issue was discovered in zzcms 8.2. user/adv.php allows remote attackers to delete arbitrary files via directory traversal sequences in the oldimg parameter. This can be leveraged for database access by deleting install.lock.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
ZZCMS | =8.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-9331 is a vulnerability in zzcms 8.2 that allows remote attackers to delete arbitrary files through directory traversal in the user/adv.php file.
Exploiting CVE-2018-9331 can lead to the deletion of critical files such as install.lock, which can allow unauthorized database access.
To mitigate CVE-2018-9331, update zzcms to a version that has addressed this vulnerability and ensure proper user input validation.
CVE-2018-9331 affects users of zzcms version 8.2 that have not implemented security measures against directory traversal attacks.
Check with the zzcms developers for any available patches or updates specifically addressing CVE-2018-9331.