CVE-2025-14837
Last modified
CVE-2025-14837 is a high-severity vulnerability rated 7.2/10 on the CVSS scale. A vulnerability has been found in ZZCMS 2025. Affected by this issue is the function stripfxg of the file /admin/siteconfig.php of the component Backend Website Settings Module. EPSS estimates a 0.39% chance of exploitation in the next 30 days.
Description
A vulnerability has been found in ZZCMS 2025. Affected by this issue is the function stripfxg of the file /admin/siteconfig.php of the component Backend Website Settings Module. Such manipulation of the argument icp leads to code injection. The attack can be executed remotely. The exploit has been disclosed to the public and may be used.
Metrics
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Zzcms | Zzcms | 2025 |
References
- https://note-hxlab.wetolink.com/share/ekNgcv2wVByaExploit, Third Party Advisory
- https://vuldb.com/?ctiid.336987Permissions Required, VDB Entry
- https://vuldb.com/?id.336987Third Party Advisory, VDB Entry
- https://vuldb.com/?submit.711655Third Party Advisory, VDB Entry
- https://note-hxlab.wetolink.com/share/ekNgcv2wVByaExploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-14837?
How severe is CVE-2025-14837?
How do I fix CVE-2025-14837?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-14831A flaw was found in GnuTLS. This vulnerability allows a deni…5.3
- CVE-2025-14832A vulnerability was identified in itsourcecode Online Cake O…9.8
- CVE-2025-14833A security flaw has been discovered in code-projects Online …9.8
- CVE-2025-14834A weakness has been identified in code-projects Simple Stock…8.8
- CVE-2025-14835The WP Photo Album Plus plugin for WordPress is vulnerable t…7.1
- CVE-2025-14836A flaw has been found in ZZCMS 2025. Affected by this vulner…2.7
- CVE-2025-1484A vulnerability exists in the media upload component of the …6.5
- CVE-2025-14840Improper Check for Unusual or Exceptional Conditions vulnera…7.5
- CVE-2025-14841A flaw has been found in OFFIS DCMTK up to 3.6.9. The impact…3.3
- CVE-2025-14842The Drag and Drop Multiple File Upload – Contact Form 7 plug…6.1
- CVE-2025-14843The Wizit Gateway for WooCommerce plugin for WordPress is vu…5.3
- CVE-2025-14844The Membership Plugin – Restrict Content plugin for WordPres…7.5
Are you affected by CVE-2025-14837?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
