zj1983 zz Unrestricted File Upload Vulnerability in ZfileAction Component
Vulnerability
A critical vulnerability allowing unrestricted file uploads has been identified in zj1983 zz versions through 2024-8. This issue arises from a lack of permission validation and file type restrictions in the ZfileAction.upload interface. The vulnerability can be exploited remotely, potentially leading to arbitrary file uploads.
Impact
Exploitation of this vulnerability allows for arbitrary file uploads, which could be used to upload malicious files that the application may execute or serve.
Reproduction
The vulnerability can be reproduced by accessing the ZfileAction.upload interface and uploading a file. No authentication or special permissions are required, and the absence of file type restrictions allows any file to be uploaded.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
