Releases80
Frequency1 month 2 weeks
Last Release
Stars239
Zikula Core Framework

CVE History

CVEPublishedCVSS v3CVSS v2
7.5 HIGH

Directory traversal vulnerability in file "jcss.php" in Zikula 1.3.x before 1.3.11 and 1.4.x before 1.4.4 on Windows allows a remote attacker to launch a PHP object injection by uploading a serialized file.