dzzoffice 2.02.1 is vulnerable to Directory Traversal via user/space/about.php.
A Cross-Site Request Forgery (CSRF) in dzzoffice 2.02.1SCUTF8 allows attackers to arbitrarily create user accounts and grant Administrator rights to regular users.
A Stored Cross Site Sripting (XSS) vulnerability exists in DzzOffice 2.02.1 via the settingnew parameter.
Dzzoffice Version 2.02.1 is affected by cross-site scripting (XSS) due to a lack of sanitization of input data at all upload functions in webroot/dzz/attach/Uploader.class.php and return a wrong response in content-type of output data in webroot/dzz/attach/controller.php.
attach/ajax.php in DzzOffice through 2.02.1 allows XSS via the editorid parameter.