CVE-2025-63695

Published
View on NVD ↗
CVSS v3
9.8
CRITICAL
CVSS v2
N/A
Affected
2
PROJECTS

Description

DzzOffice v2.3.7 and before is vulnerable to Arbitrary File Upload in /dzz/system/ueditor/php/controller.php.

dzzoffice
GitHubGitHub
4.03K
dzzoffice 文件上传导致xss
GitHubGitHub
2