fredtempez/ZwiiCMS

fredtempez/ZwiiCMS

Releases202
Frequency1 week 4 days
Last Release
Stars1
ZwiiCMS Créer facilement votre site Web sans avoir besoin de base de données. Zwii dispose d'une solide communauté ! Conçu en 2008 par Rémi Jean, le développement a été repris par Frédéric Tempez en 2018. The website manager with no database to install. Designed in 2008 by Rémi Jean, the development was taken over by Frédéric Tempez in 2018.

CVE History

CVEPublishedCVSS v3CVSS v2
4.3 MEDIUM

ZwiiCMS versions prior to 13.7.00 contain a denial-of-service vulnerability in multiple administrative endpoints due to improper authorization checks combined with flawed resource state management. When an authenticated low-privilege user requests an administrative page, the application returns "404 Not Found" as expected, but incorrectly acquires and associates a temporary lock on the targeted resource with the attacker session prior to authorization. This lock prevents other users, including administrators, from accessing the affected functionality until the attacker navigates away or the session is terminated.