Junglewise Threat Intelligence

CVE-2025-57130: ZwiiCMS incorrect access control in user management component

CVE-2025-57130 · Severity: high · CVSS 8.3 · Published 2025-11-05

Executive brief

ZwiiCMS, a content management system used for building websites, contains a security flaw in how it manages user accounts. An attacker with a standard user account can modify the profile information of any other user, including site administrators. By changing an administrator's email address and using the password reset feature, an attacker can take full control of the website.

Technical details

An Improper Access Control (CWE-284) vulnerability exists in the user management component of ZwiiCMS. A remote attacker authenticated with low-level privileges (e.g., 'Simple Member' role) can send specially crafted HTTP requests to view or modify the profile data of other users. Specifically, an attacker can change the email address associated with an administrative account. By subsequently triggering the password reset functionality, the attacker can gain full administrative access to the CMS. The vulnerability also allows unauthorized read-only access to the file manager. A fix is available in version 13.6.08.

Affected products

  • ZwiiCMS ZwiiCMS up to 13.6.07

Timeline

  • 2025-07-23: other: Initial discovery by NIVEL4 specialists
  • 2025-08-02: patched: Developer released security patch in version 13.6.08
  • 2025-11-05: disclosed: Public disclosure and CVE assignment

References

Related threats