First published: Thu Dec 09 2021(Updated: )
An Incorrect Access Control vulnerability exists in zzcms less than or equal to 2019 via admin.php. After disabling JavaScript, you can directly access the administrator console.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Zzcms Zzcms | <=2019 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-43703 is an Incorrect Access Control vulnerability in zzcms version 2019 or earlier.
CVE-2021-43703 allows an attacker to access the administrator console by disabling JavaScript.
The severity of CVE-2021-43703 is critical, with a CVSS score of 9.8.
To fix CVE-2021-43703, upgrade to a version of zzcms that is later than 2019.
You can find more information about CVE-2021-43703 in the GitHub issue #1 of the zzcms repository.