An issue in zzCMS v.2023 allows a remote attacker to execute arbitrary code and obtain sensitive information via the ueditor component in controller.php.
CVSS Details
- CVSS 3.1 Base Score: 9.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Aruba Aos 10 | — | To address the vulnerabilities described in this detail section, it is recommended to upgrade the Access Points to one of the following versions (as applicable):
- ArubaOS 10.6.x.x: 10.6.0.1 and above
- ArubaOS 10.4.x.x: 10.4.1.4 and above
- InstantOS 8.12.x.x: 8.12.0.2 and above
- InstantOS 8.10.x.x: 8.10.0.13 and above | Jan 14, 2025 | Aug 6, 2024 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub