Unrestricted File Upload in HCL ZIE for Web by HCL Software
CVE-2025-59872

4.3MEDIUM

Key Information:

Status
Vendor
CVE Published:
17 June 2026

What is CVE-2025-59872?

HCL ZIE for Web is vulnerable to an unrestricted file upload issue, which can potentially allow attackers to gain command execution on the server. If the server permits the execution of uploaded files, an attacker could upload a web shell that enables arbitrary code execution or the running of operating system commands. For exploitation to occur, the malicious file must be uploaded to the server's Webroot directory.

Affected Version(s)

ZIE 16.0

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.