Description
A SQL injection vulnerability exists in the front-end of the website in ZZCMS <= 2023, which can be exploited without any authentication. This vulnerability could potentially allow attackers to gain unauthorized access to the database and extract sensitive information.
References (2)
Core 2
Core References
Broken Link, Product
http://www.zzcms.net/
Broken Link, Exploit, Third Party Advisory
https://github.com/youyouiooi/vulnerability-reports/blob/main/CVE-2025-22957/REANDE.md
Scores
CVSS v3
9.8
EPSS
0.0052
EPSS Percentile
40.6%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
total
Details
CWE
CWE-89
Status
published
Products (1)
zzcms/zzcms
< 2023
Published
Jan 31, 2025
Tracked Since
Feb 18, 2026