Back to CVE List

CVE-2025-59872

MEDIUM SEVERITY

CVSS Score & Metrics

Base Score
4.3 / 10
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Vulnerability Description

HCL ZIE for Web is affetced by an Unrestricted File Upload vulnerability, If the server is configured to execute code, then it may be possible to obtain command execution on the server by uploading a file known as a web shell, which allows you to execute arbitrary code or operating system commands. For this attack to be successful, the file needs to be uploaded inside the Webroot, and the server must be configured to execute the code

Vulnerability Details

Published Date
Last Modified
CWE ID
CWE-209
Source
NVD
Vendor
HCL Software
Product
ZIE

External References

Discussion (0)

Add Comment

No comments yet. Be the first!