First published: Sun Mar 02 2025(Updated: )
A vulnerability, which was classified as critical, has been found in zj1983 zz up to 2024-8. Affected by this issue is the function sendNotice of the file src/main/java/com/futvan/z/erp/customer_notice/Customer_noticeAction.java of the component HTTP Request Handler. The manipulation of the argument url leads to server-side request forgery. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Credit: cna@vuldb.com
Affected Software | Affected Version | How to fix |
---|---|---|
zj1983 zz | <=2024-8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-1833 is classified as a critical vulnerability.
CVE-2025-1833 affects the HTTP Request Handler in the zj1983 zz application up to version 2024-8.
To fix CVE-2025-1833, upgrade to a version of zj1983 zz that is later than 2024-8.
CVE-2025-1833 impacts the 'sendNotice' function in the Customer_noticeAction.java file.
The vendor for the affected product is zj1983.