CVE-2019-16720 describes an unrestricted file upload vulnerability in ZZZCMS zzzphp v1.7.2. Specifically, the plugins/ueditor/php/controller.php?upfolder=news&action=catchimage component fails to properly validate uploaded file types, allowing attackers to upload malicious files like .htaccess or .php5. This vulnerability carries a CVSS v3.1 score of 7.5 (HIGH), indicating that it can be exploited remotely with low attack complexity and no user interaction, leading to high integrity impacts. While no public exploit intelligence (Metasploit, Nuclei, ExploitDB) or active exploitation has been observed, and community discussion is minimal, the potential for arbitrary code execution remains significant.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.7.2CPE matchmatch criteria | cpe:2.3:a:zzzcms:zzzphp:1.7.2:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.