CVE-2021-37144

CRITICAL

CSZ CMS 1.2.9 - Privilege Escalation

Title source: llm

Description

CSZ CMS 1.2.9 is vulnerable to Arbitrary File Deletion. This occurs in PHP when the unlink() function is called and user input might affect portions of or the whole affected parameter, which represents the path of the file to remove, without sufficient sanitization.

Scores

CVSS v3 9.1
EPSS 0.0029
EPSS Percentile 52.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H

Classification

CWE
CWE-706
Status published

Affected Products (1)

cszcms/csz_cms

Timeline

Published Jul 30, 2021
Tracked Since Feb 18, 2026