Description
A vulnerability was identified in Sanluan PublicCMS up to 6.202506.d. Affected by this vulnerability is the function ZipSecureFile.setMinflateRatio of the file common/src/main/java/com/publiccms/common/tools/DocToHtmlUtils.java. Such manipulation leads to resource consumption. It is possible to launch the attack remotely. The vendor was contacted early about this disclosure but did not respond in any way.
Problem types
Product status
6.202506.b
6.202506.c
6.202506.d
Timeline
| 2026-04-21: | Advisory disclosed |
| 2026-04-21: | VulDB entry created |
| 2026-04-21: | VulDB entry last update |
Credits
LeyNn3H (VulDB User)
VulDB CNA Team
References
vuldb.com/vuln/358491 (VDB-358491 | Sanluan PublicCMS DocToHtmlUtils.java ZipSecureFile.setMinflateRatio resource consumption)
vuldb.com/vuln/358491/cti (VDB-358491 | CTI Indicators (IOB, IOC, TTP, IOA))
vuldb.com/submit/794798 (Submit #794798 | PublicCMS V6.202506.d Improper Handling of Highly Compressed Data (Data Amplification))