CVE-2025-59872: HCL ZIE for Web is affetced by an Unrestricted File Upload vulnerability,

Published Jun 17, 2026
·
Updated

HCL ZIE for Web is affetced by an Unrestricted File Upload vulnerability, If the server is configured to execute code, then it may be possible to obtain command execution on the server by uploading a file known as a web shell, which allows you to execute arbitrary code or operating system commands. For this attack to be successful, the file needs to be uploaded inside the Webroot, and the server must be configured to execute the code

Affected Software

2 affected components
HCL ZIE for Web
hcltech Zie For Web=16.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Compensating control

    Ensure the webroot (document root) cannot execute uploaded files; configure the server so that files placed in the webroot are not treated as executable code (e.g., disable/limit script execution in the upload directory) to prevent web-shell command execution.

Event History

Jun 17, 2026
CVE Published
via MITRE·12:32 PM
Data Sourced
via MITRE·12:32 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·01:19 PM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2025-59872?

CVE-2025-59872 has a medium severity rating of 4.3.

2

What systems are affected by CVE-2025-59872?

CVE-2025-59872 affects HCL ZIE for Web software.

3

How do I fix CVE-2025-59872?

To fix CVE-2025-59872, ensure proper configuration of file upload handling and restrict file types that can be uploaded.

4

What are the risks associated with CVE-2025-59872?

The primary risk of CVE-2025-59872 is the potential for unauthorized command execution on the server through uploaded malicious files.

5

Can CVE-2025-59872 lead to system compromise?

Yes, if exploited, CVE-2025-59872 can lead to system compromise by allowing attackers to execute arbitrary code.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203