PT-2026-22784 · Zdir Pro · Zdir Pro

CVE-2025-66945

·

Publicado

2026-03-03

·

Atualizado

2026-03-04

CVSS v3.1

9.1

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Zdir Pro versions 4.x
Description A path traversal issue exists in the ZIP extraction functionality of Zdir Pro. Processing a specially crafted ZIP archive via the backend at /api/extract can allow files to be written outside the intended directory. This could lead to arbitrary file overwrites and potentially remote code execution. The vulnerable component is the ZIP extraction API. The vulnerable API endpoint is /api/extract.
Recommendations Apply updates to address the path traversal issue in the ZIP extraction functionality.

Exploit

Correção

RCE

Memory Corruption

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2025-66945

Produtos afetados

Zdir Pro