Arbitrary File Deletion in CSZ CMS by CSKaza
CVE-2021-37144

9.1CRITICAL

Key Information:

Vendor

Cszcms

Status
Vendor
CVE Published:
30 July 2021

What is CVE-2021-37144?

CSZ CMS version 1.2.9 contains a vulnerability that allows unauthorized users to delete arbitrary files from the server. This security flaw arises from improper handling of input data in the unlink() function, which can lead to file paths being manipulated without adequate sanitization. As a result, attackers may exploit this vulnerability to remove critical files, jeopardizing the integrity and availability of the targeted applications. It is essential for users of CSZ CMS to review their systems and apply necessary updates to mitigate this risk.

References

CVSS V3.1

Score:
9.1
Severity:
CRITICAL
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2021-37144 : Arbitrary File Deletion in CSZ CMS by CSKaza