PatchSiren

zsadmin2025 CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

LOW zsadmin2025 CVE published 2026-07-21

CVE-2026-16451

A security flaw has been discovered in ZS-Admin up to b52e14536d59fda11e56e2536a1c32e82a38cead, impacting the /api/system/file/upload function of com.zs.file.controller.SysFileController. The vulnerability allows unrestricted file uploads through manipulation of the File argument and can be exploited remotely. The project uses a rolling release model, making version details for affected or updated release [truncated]

LOW zsadmin2025 CVE published 2026-07-21

CVE-2026-16449

A sql injection vulnerability was found in zsadmin2025 ZS-Admin up to b52e14536d59fda11e56e2536a1c32e82a38cead. The vulnerability exists in the function OrderItem.asc/OrderItem.desc of the file /api/system/sys/dept/page of the component com.zs.sys.dept.controller.SysDeptController. This manipulation of the argument orderField causes sql injection. The attack is possible to be carried out remotely. The exp [truncated]