CVE-2023-45555: Malicious File Upload
Published Oct 24, 2023
·Updated
File Upload vulnerability in zzzCMS v.2.1.9 allows a remote attacker to execute arbitrary code via a crafted file to the downurl function in zzz.php file.
Affected Software
1 affected component
ZZZCMS ZZZCMS=2.1.9
Event History
Oct 24, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is CVE-2023-45555?
CVE-2023-45555 is a file upload vulnerability in zzzCMS v.2.1.9 that allows a remote attacker to execute arbitrary code.
2
How does the vulnerability in zzzCMS v.2.1.9 occur?
The vulnerability in zzzCMS v.2.1.9 occurs due to a file upload vulnerability in the down_url function in the zzz.php file.
3
What is the severity of CVE-2023-45555?
CVE-2023-45555 has a severity rating of high (7.8).
4
How can a remote attacker exploit CVE-2023-45555?
A remote attacker can exploit CVE-2023-45555 by uploading a crafted file to the down_url function in the zzz.php file.
5
Is there a fix available for CVE-2023-45555?
It is recommended to update to a patched version of zzzCMS that addresses the file upload vulnerability.