CVE-2025-57130
8.3ZwiiCMS · ZwiiCMS
A privilege escalation vulnerability in ZwiiCMS allows authenticated users to modify the profile data of other users, including administrators, via crafted HTTP requests.
Executive summary
An incorrect access control vulnerability in ZwiiCMS up to v13.6.07 permits authenticated attackers to escalate privileges and perform unauthorized modifications to user accounts.
Vulnerability
This is an incorrect access control flaw within the user management component that allows a remote, authenticated user to bypass intended restrictions. By submitting a specially crafted HTTP request, an attacker can modify the profile data of any other user in the system, including administrative accounts.
Business impact
The ability for a low-privilege attacker to modify administrator profile data poses a severe threat to the integrity and confidentiality of the entire content management system. With a CVSS score of 8.3, this high-severity flaw could lead to full administrative account takeover, unauthorized data access, or the deployment of malicious content, resulting in significant operational and reputational damage.
Remediation
Immediate Action: Monitor official ZwiiCMS security channels for the release of a security patch and apply it immediately upon availability.
Proactive Monitoring: Review application access logs for unusual HTTP requests targeting user profile modification endpoints or unexpected changes to administrative account attributes.
Compensating Controls: Implement strict Web Application Firewall (WAF) rules to filter or block suspicious requests directed at user management parameters, particularly those originating from non-administrative sessions.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Given the high CVSS score and the critical nature of privilege escalation, administrators must treat this vulnerability with high priority. While a specific patch version remains to be confirmed, teams should proactively audit their user management configurations and remain ready to update the software as soon as the vendor provides a remediation. Failure to address this could result in a complete compromise of the CMS administrative environment.