CVE-2021-37144

CRITICAL

CSZ CMS 1.2.9 - Privilege Escalation

Title source: llm
STIX 2.1

Description

CSZ CMS 1.2.9 is vulnerable to Arbitrary File Deletion. This occurs in PHP when the unlink() function is called and user input might affect portions of or the whole affected parameter, which represents the path of the file to remove, without sufficient sanitization.

Scores

CVSS v3 9.1
EPSS 0.0029
EPSS Percentile 52.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H

Details

CWE
CWE-706
Status published
Products (1)
cszcms/csz_cms 1.2.9
Published Jul 30, 2021
Tracked Since Feb 18, 2026