Arbitrary File Deletion in CSZ CMS by CSKaza
CVE-2021-37144
9.1CRITICAL
What is CVE-2021-37144?
CSZ CMS version 1.2.9 contains a vulnerability that allows unauthorized users to delete arbitrary files from the server. This security flaw arises from improper handling of input data in the unlink() function, which can lead to file paths being manipulated without adequate sanitization. As a result, attackers may exploit this vulnerability to remove critical files, jeopardizing the integrity and availability of the targeted applications. It is essential for users of CSZ CMS to review their systems and apply necessary updates to mitigate this risk.
