Home

Description

An Incorrect Access Control vulnerability in the user management component of ZwiiCMS up to v13.6.07 allows a remote, authenticated attacker to escalate their privileges. By sending a specially crafted HTTP request, a low-privilege user can access and modify the profile data of any other user, including administrators.

PUBLISHED Reserved 2025-08-17 | Published 2025-11-05 | Updated 2025-11-05 | Assigner mitre




HIGH: 8.3CVSS:3.1/AC:L/AV:N/A:L/C:H/I:H/PR:L/S:U/UI:N

References

zwiicms.com

blog.nivel4.com/...de-alta-severidad-en-gestor-de-contenidos

cve.org (CVE-2025-57130)

nvd.nist.gov (CVE-2025-57130)

Download JSON