What the vulnerability does
01Description
Unrestricted Upload of File with Dangerous Type vulnerability in URBAN BASE Z-Downloads.This issue affects Z-Downloads: from n/a through 1.11.3.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
What the vulnerability does
Unrestricted Upload of File with Dangerous Type vulnerability in URBAN BASE Z-Downloads.This issue affects Z-Downloads: from n/a through 1.11.3.
Explanation of Vulnerability in Simple Terms
Z-Downloads versions up to 1.11.3 allow unauthenticated attackers to upload arbitrary files to the server without restriction. An attacker can upload malicious files—such as PHP scripts—to gain control of the site. The vulnerability requires no authentication or user interaction, making it trivial to exploit remotely. Update to version 1.12.1 or later.
What an attacker can do
Upload arbitrary files, including executable code, to the server without authentication.
Potential impact on your site
Attackers can upload malicious files and execute code on your site, leading to complete compromise.
Conditions required to exploit
Network access only; no authentication or user interaction required.
Key dates
External resources
Related vulnerabilities