← back
CVE-2025-57130highCWE-284

CVE-2025-57130

21Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 8.3epss 0.4%
exploitation probability
0.4%top 70% of all CVEs
observed exploitation
nono source reports it
An Incorrect Access Control vulnerability in the user management component of ZwiiCMS up to v13.6.07 allows a remote, authenticated attacker to escalate their privileges. By sending a specially crafted HTTP request, a low-privilege user can access and modify the profile data of any other user, including administrators.
CVSS:3.1/AC:L/AV:N/A:L/C:H/I:H/PR:L/S:U/UI:N
Affected products
n/a · n/a