Executive brief
ZwiiCMS, a content management system used for building websites, contains a security flaw in how it manages user accounts. An attacker with a standard user account can modify the profile information of any other user, including site administrators. By changing an administrator's email address and using the password reset feature, an attacker can take full control of the website.
Technical details
An Improper Access Control (CWE-284) vulnerability exists in the user management component of ZwiiCMS. A remote attacker authenticated with low-level privileges (e.g., 'Simple Member' role) can send specially crafted HTTP requests to view or modify the profile data of other users. Specifically, an attacker can change the email address associated with an administrative account. By subsequently triggering the password reset functionality, the attacker can gain full administrative access to the CMS. The vulnerability also allows unauthorized read-only access to the file manager. A fix is available in version 13.6.08.
Affected products
- ZwiiCMS ZwiiCMS up to 13.6.07
Timeline
- 2025-07-23: other: Initial discovery by NIVEL4 specialists
- 2025-08-02: patched: Developer released security patch in version 13.6.08
- 2025-11-05: disclosed: Public disclosure and CVE assignment