Junglewise Threat Intelligence

CVE-2025-52239: ZKEASOFT ZKEACMS arbitrary file upload in file upload component

CVE-2025-52239 · Severity: critical · CVSS 9.8 · Published 2025-08-04

Executive brief

ZKEACMS, a content management system used for building websites, contains a critical security flaw that allows unauthorized users to upload malicious files. By exploiting this vulnerability, an attacker can take full control of the web server and execute arbitrary commands. This could lead to the theft of sensitive customer data, complete website defacement, or the use of the server for further attacks.

Technical details

An unrestricted file upload vulnerability (CWE-434) exists in ZKEACMS v4.1. The application fails to properly validate or sanitize file extensions and content types during the upload process. A remote attacker can exploit this by uploading a malicious script (such as a web shell) to the server. Because the attack vector is network-based and requires no authentication or user interaction, it allows for complete system compromise, including unauthorized data access and arbitrary code execution. A proof-of-concept has been identified in public repositories.

Affected products

  • ZKEASOFT ZKEACMS 4.1

Timeline

  • 2025-08-04: advisory: Initial disclosure and NVD publication
  • 2025-08-04: disclosed: CISA-ADP enrichment and CVSS scoring provided

References