PT-2026-22784 · Zdir Pro · Zdir Pro
CVE-2025-66945
·
Publicado
2026-03-03
·
Atualizado
2026-03-04
CVSS v3.1
9.1
Crítica
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Zdir Pro versions 4.x
Description
A path traversal issue exists in the ZIP extraction functionality of Zdir Pro. Processing a specially crafted ZIP archive via the backend at
/api/extract can allow files to be written outside the intended directory. This could lead to arbitrary file overwrites and potentially remote code execution. The vulnerable component is the ZIP extraction API. The vulnerable API endpoint is /api/extract.Recommendations
Apply updates to address the path traversal issue in the ZIP extraction functionality.
Exploit
Correção
RCE
Memory Corruption
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Zdir Pro