YZNCMS Arbitrary File Upload Vulnerability Allowing Code Execution

Vulnerability

A vulnerability allowing arbitrary file upload has been identified in the plugin installation feature of YZNCMS version 2.0.1. This vulnerability allows attackers to execute arbitrary code by uploading a specially crafted Zip file.

Impact

Exploitation of this vulnerability could lead to unauthorized code execution on the server where YZNCMS is installed.

Reproduction

To reproduce this vulnerability, upload a crafted Zip file through the plugin installation feature in YZNCMS version 2.0.1. The uploaded Zip file can be designed to include malicious code that will be executed on the server.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
1.0
impact
10.0
exploitability
9.7
remediation
0.0
relevance
0.0
threat
6.4
urgency
2.9
incentive
10.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.