First published: Fri Jan 31 2025(Updated: )
A SQL injection vulnerability exists in the front-end of the website in ZZCMS <= 2023, which can be exploited without any authentication. This vulnerability could potentially allow attackers to gain unauthorized access to the database and extract sensitive information.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
ZZCMS | <=2023 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-22957 is a critical SQL injection vulnerability that can be exploited without authentication.
To fix CVE-2025-22957, update ZZCMS to a version higher than 2023 and apply relevant security patches.
Attackers can exploit CVE-2025-22957 to gain unauthorized access to the database and retrieve sensitive information.
Yes, CVE-2025-22957 can be exploited easily as it does not require any authentication.
ZZCMS versions up to and including 2023 are affected by CVE-2025-22957.