Description
A flaw has been found in ZZCMS 2025. Affected by this vulnerability is an unknown functionality of the file /reg/user_save.php of the component User Data Storage Module. This manipulation causes cleartext storage in a file or on disk. Remote exploitation of the attack is possible. The exploit has been published and may be used.
Problem types
Cleartext Storage in a File or on Disk
Cleartext Storage of Sensitive Information
Timeline
| 2025-12-17: | Advisory disclosed |
| 2025-12-17: | VulDB entry created |
| 2025-12-17: | VulDB entry last update |
Credits
airrudder (VulDB User)
References
note-hxlab.wetolink.com/share/bu2KYevoyBm6
vuldb.com/?id.336986 (VDB-336986 | ZZCMS User Data Storage user_save.php cleartext storage in a file or on disk)
vuldb.com/?ctiid.336986 (VDB-336986 | CTI Indicators (IOB, IOC, TTP, IOA))
vuldb.com/?submit.711654 (Submit #711654 | zzcms zzcms2025 Plaintext Password in Configuration File)
note-hxlab.wetolink.com/share/bu2KYevoyBm6
Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.