CVE-2025-22957

A SQL injection vulnerability exists in the front-end of the website in ZZCMS <= 2023, which can be exploited without any authentication. This vulnerability could potentially allow attackers to gain unauthorized access to the database and extract sensitive information.
References
Link Resource
http://www.zzcms.net/ Broken Link Product
https://github.com/youyouiooi/vulnerability-reports/blob/main/CVE-2025-22957/REANDE.md Broken Link Exploit Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:zzcms:zzcms:*:*:*:*:*:*:*:*

History

22 Apr 2025, 15:37

Type Values Removed Values Added
References () http://www.zzcms.net/ - () http://www.zzcms.net/ - Broken Link, Product
References () https://github.com/youyouiooi/vulnerability-reports/blob/main/CVE-2025-22957/REANDE.md - () https://github.com/youyouiooi/vulnerability-reports/blob/main/CVE-2025-22957/REANDE.md - Broken Link, Exploit, Third Party Advisory
First Time Zzcms
Zzcms zzcms
CPE cpe:2.3:a:zzcms:zzcms:*:*:*:*:*:*:*:*

20 Mar 2025, 16:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
CWE CWE-89

18 Feb 2025, 19:15

Type Values Removed Values Added
CWE CWE-89
CVSS v2 : unknown
v3 : 9.8
v2 : unknown
v3 : unknown

03 Feb 2025, 17:15

Type Values Removed Values Added
Summary
  • (es) Existe una vulnerabilidad de inyección SQL en el front-end del sitio web en ZZCMS &lt;= 2023, que puede explotarse sin ninguna autenticación. Esta vulnerabilidad podría permitir a los atacantes obtener acceso no autorizado a la base de datos y extraer información confidencial.
CWE CWE-89
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8

31 Jan 2025, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-01-31 17:15

Updated : 2025-04-22 15:37


NVD link : CVE-2025-22957

Mitre link : CVE-2025-22957

CVE.ORG link : CVE-2025-22957


JSON object : View

Products Affected

zzcms

  • zzcms
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')