Executive brief
ZKEACMS, a content management system used for building websites, contains a critical security flaw that allows unauthorized users to upload malicious files. By exploiting this vulnerability, an attacker can take full control of the web server and execute arbitrary commands. This could lead to the theft of sensitive customer data, complete website defacement, or the use of the server for further attacks.
Technical details
An unrestricted file upload vulnerability (CWE-434) exists in ZKEACMS v4.1. The application fails to properly validate or sanitize file extensions and content types during the upload process. A remote attacker can exploit this by uploading a malicious script (such as a web shell) to the server. Because the attack vector is network-based and requires no authentication or user interaction, it allows for complete system compromise, including unauthorized data access and arbitrary code execution. A proof-of-concept has been identified in public repositories.
Affected products
- ZKEASOFT ZKEACMS 4.1
Timeline
- 2025-08-04: advisory: Initial disclosure and NVD publication
- 2025-08-04: disclosed: CISA-ADP enrichment and CVSS scoring provided