First published: Fri Sep 15 2023(Updated: )
An issue in zzCMS v.2023 allows a remote attacker to execute arbitrary code and obtain sensitive information via the ueditor component in controller.php.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Zzcms Zzcms | =2023 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-42398 is a critical vulnerability in zzCMS v.2023 that allows a remote attacker to execute arbitrary code and obtain sensitive information.
CVE-2023-42398 occurs due to a vulnerability in the ueditor component in controller.php of zzCMS v.2023, which can be exploited by a remote attacker.
CVE-2023-42398 is classified as critical with a severity value of 9.8 (out of 10).
CVE-2023-42398 can be exploited by a remote attacker through the ueditor component in controller.php of zzCMS v.2023.
At the moment, there is no known fix for CVE-2023-42398. It is recommended to apply mitigations or consider upgrading to a patched version when available.