PT-2025-38659 · Unknown · Seriawei Zkeacms

·

CVE-2025-10764

·

Published

2025-09-21

·

Updated

2025-10-14

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SeriaWei ZKEACMS versions prior to 4.4
Description A vulnerability exists in SeriaWei ZKEACMS up to version 4.3. The issue affects the Edit function within the src/ZKEACMS.EventAction/Controllers/PendingTaskController.cs file of the Event Action System component. Manipulation of the Data argument can lead to server-side request forgery. The attack can be performed remotely. The exploit is publicly available.
Recommendations Update SeriaWei ZKEACMS to version 4.4 or later. As a temporary workaround, restrict access to the Edit function within the src/ZKEACMS.EventAction/Controllers/PendingTaskController.cs file. Avoid using the Data parameter in the Edit function until the issue is resolved.

Exploit

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-10764

Affected Products

Seriawei Zkeacms