{"dataType":"CVE_RECORD","dataVersion":"5.1","cveMetadata":{"cveId":"CVE-2023-5263","assignerOrgId":"1af790b2-7ee1-4545-860a-a788eba489b5","state":"PUBLISHED","assignerShortName":"VulDB","dateReserved":"2023-09-29T05:25:13.272Z","datePublished":"2023-09-29T14:00:07.851Z","dateUpdated":"2025-06-18T14:06:30.738Z"},"containers":{"cna":{"providerMetadata":{"orgId":"1af790b2-7ee1-4545-860a-a788eba489b5","shortName":"VulDB","dateUpdated":"2023-10-24T19:48:43.349Z"},"title":"ZZZCMS Database Backup File save.php restore permission","problemTypes":[{"descriptions":[{"type":"CWE","cweId":"CWE-275","lang":"en","description":"CWE-275 Permission Issues"}]}],"affected":[{"vendor":"n/a","product":"ZZZCMS","versions":[{"version":"2.1.7","status":"affected"}],"modules":["Database Backup File Handler"]}],"descriptions":[{"lang":"en","value":"A vulnerability was found in ZZZCMS 2.1.7 and classified as critical. Affected by this issue is the function restore of the file /admin/save.php of the component Database Backup File Handler. The manipulation leads to permission issues. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-240872."},{"lang":"de","value":"Eine Schwachstelle wurde in ZZZCMS 2.1.7 gefunden. Sie wurde als kritisch eingestuft. Dies betrifft die Funktion restore der Datei /admin/save.php der Komponente Database Backup File Handler. Mittels dem Manipulieren mit unbekannten Daten kann eine permission issues-Schwachstelle ausgenutzt werden. Der Angriff kann über das Netzwerk passieren. Der Exploit steht zur öffentlichen Verfügung."}],"metrics":[{"cvssV3_1":{"version":"3.1","baseScore":6.3,"vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","baseSeverity":"MEDIUM"}},{"cvssV3_0":{"version":"3.0","baseScore":6.3,"vectorString":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","baseSeverity":"MEDIUM"}},{"cvssV2_0":{"version":"2.0","baseScore":6.5,"vectorString":"AV:N/AC:L/Au:S/C:P/I:P/A:P"}}],"timeline":[{"time":"2023-09-29T00:00:00.000Z","lang":"en","value":"Advisory disclosed"},{"time":"2023-09-29T00:00:00.000Z","lang":"en","value":"CVE reserved"},{"time":"2023-09-29T02:00:00.000Z","lang":"en","value":"VulDB entry created"},{"time":"2023-10-22T08:50:45.000Z","lang":"en","value":"VulDB entry last update"}],"credits":[{"lang":"en","value":"jamspilly (VulDB User)","type":"analyst"}],"references":[{"url":"https://vuldb.com/?id.240872","tags":["vdb-entry","technical-description"]},{"url":"https://vuldb.com/?ctiid.240872","tags":["signature","permissions-required"]},{"url":"https://github.com/yhy217/zzzcms-vul/issues/1","tags":["exploit","issue-tracking"]}]},"adp":[{"providerMetadata":{"orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE","dateUpdated":"2024-08-02T07:52:08.549Z"},"title":"CVE Program Container","references":[{"url":"https://vuldb.com/?id.240872","tags":["vdb-entry","technical-description","x_transferred"]},{"url":"https://vuldb.com/?ctiid.240872","tags":["signature","permissions-required","x_transferred"]},{"url":"https://github.com/yhy217/zzzcms-vul/issues/1","tags":["exploit","issue-tracking","x_transferred"]}]},{"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2025-06-18T14:06:16.022948Z","id":"CVE-2023-5263","options":[{"Exploitation":"poc"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2025-06-18T14:06:30.738Z"}}]}}