CVE-2025-1849
CVSS 3.1 Score 6.3 of 10 (medium)
Details
Published Mar 3, 2025
CWE ID 918
Summary
CVE-2025-1849 is a critical vulnerability affecting zj1983 zz up to version 2024-8. The issue lies in an unknown functionality of the file /import_data_todb. An attacker can manipulate the argument url to initiate server-side request forgery, allowing them to execute arbitrary commands. This vulnerability can be exploited remotely, making it a significant threat. Unfortunately, the exploit has been made public, increasing the risk for potential attacks. Despite early disclosure to the vendor, they have yet to respond or provide a patch.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Z Z