← Back to CVE List

CVE-2025-1949

Published: 2025-03-04T19:15Z
Last Modified: 2025-03-04T20:15Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
A vulnerability, which was classified as problematic, has been found in ZZCMS 2025. This issue affects some unknown processing of the file /3/ucenter_api/code/register_nodb.php of the component URL Handler. The manipulation of the argument $_SERVER['PHP_SELF'] leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt