A weakness has been identified in SeriaWei ZKEACMS up to 4.3. This issue affects the function Download of the file EventViewerController.cs. Executing manipulation of the argument ID can lead to path traversal. It is possible to launch the attack remotely. The exploit has been made available to the public and could be exploited. The vendor was contacted early about this disclosure but did not respond in any way.
References
Link | Resource |
---|---|
https://github.com/August829/YU1/issues/1 | Issue Tracking Third Party Advisory |
https://vuldb.com/?ctiid.325121 | Permissions Required VDB Entry |
https://vuldb.com/?id.325121 | Third Party Advisory VDB Entry |
https://vuldb.com/?submit.650445 | Third Party Advisory VDB Entry |
Configurations
History
14 Oct 2025, 19:59
Type | Values Removed | Values Added |
---|---|---|
References | () https://github.com/August829/YU1/issues/1 - Issue Tracking, Third Party Advisory | |
References | () https://vuldb.com/?ctiid.325121 - Permissions Required, VDB Entry | |
References | () https://vuldb.com/?id.325121 - Third Party Advisory, VDB Entry | |
References | () https://vuldb.com/?submit.650445 - Third Party Advisory, VDB Entry | |
CPE | cpe:2.3:a:zkea:zkeacms:*:*:*:*:*:*:*:* | |
First Time |
Zkea zkeacms
Zkea |
21 Sep 2025, 07:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-09-21 07:15
Updated : 2025-10-14 19:59
NVD link : CVE-2025-10766
Mitre link : CVE-2025-10766
CVE.ORG link : CVE-2025-10766
JSON object : View
Products Affected
zkea
- zkeacms
CWE
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')