Unrestricted File Upload in HCL ZIE for Web by HCL Software
CVE-2025-59872
4.3MEDIUM
What is CVE-2025-59872?
HCL ZIE for Web is vulnerable to an unrestricted file upload issue, which can potentially allow attackers to gain command execution on the server. If the server permits the execution of uploaded files, an attacker could upload a web shell that enables arbitrary code execution or the running of operating system commands. For exploitation to occur, the malicious file must be uploaded to the server's Webroot directory.
Affected Version(s)
ZIE 16.0
