zj1983 zz Unrestricted File Upload Vulnerability in ZfileAction Component

Vulnerability

A critical vulnerability allowing unrestricted file uploads has been identified in zj1983 zz versions through 2024-8. This issue arises from a lack of permission validation and file type restrictions in the ZfileAction.upload interface. The vulnerability can be exploited remotely, potentially leading to arbitrary file uploads.

Impact

Exploitation of this vulnerability allows for arbitrary file uploads, which could be used to upload malicious files that the application may execute or serve.

Reproduction

The vulnerability can be reproduced by accessing the ZfileAction.upload interface and uploading a file. No authentication or special permissions are required, and the absence of file type restrictions allows any file to be uploaded.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
8.7
remediation
0.0
relevance
0.0
threat
6.4
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.