A security flaw has been discovered in ZS-Admin up to b52e14536d59fda11e56e2536a1c32e82a38cead, impacting the /api/system/file/upload function of com.zs.file.controller.SysFileController. The vulnerability allows unrestricted file uploads through manipulation of the File argument and can be exploited remotely. The project uses a rolling release model, making version details for affected or updated release [truncated]
A sql injection vulnerability was found in zsadmin2025 ZS-Admin up to b52e14536d59fda11e56e2536a1c32e82a38cead. The vulnerability exists in the function OrderItem.asc/OrderItem.desc of the file /api/system/sys/dept/page of the component com.zs.sys.dept.controller.SysDeptController. This manipulation of the argument orderField causes sql injection. The attack is possible to be carried out remotely. The exp [truncated]