CVE-2018-16344: Zzcms
High severity, CVSS 7.5. EPSS: 1.9% chance of exploitation in the next 30 days.
An issue was discovered in zzcms 8.3. It allows remote attackers to delete arbitrary files via directory traversal sequences in the flv parameter. This can be leveraged for database access by deleting install.lock.
Affected products
- Zzcms Zzcms: version 8.3 only
Published 2018-09-02. Last modified 2026-06-17.