CVE detail
CVE-2019-16720 — CVE-2019-16720
Published 2019-09-23 · Modified 2026-06-17 · Vendor zzzcms · Product zzzphp · Source nvd
HIGH
severity
CVSS-derived band
0.0144
EPSS probability
exploitation probability, 30d
71.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
ZZZCMS zzzphp v1.7.2 does not properly restrict file upload in plugins/ueditor/php/controller.php?upfolder=news&action=catchimage, as demonstrated by uploading a .htaccess or .php5 file.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References