First published: Mon Mar 03 2025(Updated: )
A vulnerability classified as critical has been found in zj1983 zz up to 2024-8. Affected is an unknown function of the file /import_data_check. The manipulation of the argument url leads to server-side request forgery. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Credit: cna@vuldb.com
Affected Software | Affected Version | How to fix |
---|---|---|
zj1983 zz | <=2024-8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-1848 is classified as a critical vulnerability.
To fix CVE-2025-1848, it is recommended to update the software to a version later than 2024-8.
CVE-2025-1848 allows for server-side request forgery attacks.
CVE-2025-1848 affects zj1983 zz up to version 2024-8.
Yes, CVE-2025-1848 can be exploited remotely.