CVE-2021-43703
CRITICALCVSS 9.8/10EPSS 1.80%
Last modified
CVE-2021-43703 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. An Incorrect Access Control vulnerability exists in zzcms less than or equal to 2019 via admin.php. After disabling JavaScript, you can directly access the administrator console.. EPSS estimates a 1.80% chance of exploitation in the next 30 days.
Description
An Incorrect Access Control vulnerability exists in zzcms less than or equal to 2019 via admin.php. After disabling JavaScript, you can directly access the administrator console.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Zzcms | Zzcms | <= 2019 |
References
- https://github.com/forget-code/zzcms/issues/1Exploit, Third Party Advisory
- https://github.com/forget-code/zzcms/issues/1Exploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-43703?
An Incorrect Access Control vulnerability exists in zzcms less than or equal to 2019 via admin.php. After disabling JavaScript, you can directly access the administrator console.
How severe is CVE-2021-43703?
CVE-2021-43703 has a CVSS score of 9.8/10 (CRITICAL severity). The EPSS model estimates a 1.80% probability of exploitation in the next 30 days.
How do I fix CVE-2021-43703?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2021
- CVE-2021-43697Workerman-ThinkPHP-Redis (last update Mar 16, 2018) is affec…6.1
- CVE-2021-43698phpWhois (last update Jun 30 2021) is affected by a Cross Si…6.1
- CVE-2021-4370The uListing plugin for WordPress is vulnerable to authoriza…9.8
- CVE-2021-43700An issue was discovered in ApiManager 1.1. there is sql inje…9.8
- CVE-2021-43701CSZ CMS 1.2.9 has a Time and Boolean-based Blind SQL Injecti…6.5
- CVE-2021-43702ASUS RT-A88U 3.0.0.4.386_45898 is vulnerable to Cross Site S…9
- CVE-2021-43707Cross Site Scripting (XSS) vulnerability exists in Maccms v1…6.1
- CVE-2021-43708The Labeling tool in Titus Classification Suite 18.8.1910.14…5.5
- CVE-2021-4371The WP Quick FrontEnd Editor plugin for WordPress is vulnera…4.3
- CVE-2021-43711The downloadFlile.cgi binary file in TOTOLINK EX200 V4.0.3c.…9.8
- CVE-2021-43712Stored XSS in Add New Employee Form in Sourcecodester Employ…5.4
- CVE-2021-4372The WooCommerce Dynamic Pricing and Discounts plugin for Wor…6.1
Are you affected by CVE-2021-43703?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
