Juzaweb CMS Improper Authorization Vulnerability in Import Page

Vulnerability

A critical vulnerability has been identified in Juzaweb CMS version 3.4.2, specifically within the Import Page component. The issue arises from an unknown function in the file '/admin-cp/imports', leading to improper authorization. This vulnerability allows unprivileged users to access functions related to file imports, enabling them to import arbitrary files into the CMS. The vulnerability can be exploited remotely, and a public exploit is available.

Impact

Exploitation of this vulnerability allows low-privileged users to bypass authorization and import arbitrary files into the CMS, potentially leading to further exploitation or unauthorized access.

Reproduction

To reproduce this vulnerability, create a new user and assign it a role with all permissions disabled. Log in with this account and navigate to the '/admin-cp/imports' page. The user will be able to import files into the CMS, despite having no import permissions.

Added: Sep 1, 2025, 7:22 PM
Updated: Sep 1, 2025, 7:22 PM

Vulnerability Rating

Custom Algorithm
spread
1.0
impact
0.6
exploitability
6.8
remediation
0.0
relevance
0.2
threat
6.4
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.