ZwiiCMS versions prior to 13.7.00 contain a denial-of-service vulnerability in multiple administrative endpoints due to improper authorization checks combined with flawed resource state management. When an authenticated low-privilege user requests an administrative page, the application returns "404 Not Found" as expected, but incorrectly acquires and associates a temporary lock on the targeted resource with the attacker session prior to authorization. This lock prevents other users, including administrators, from accessing the affected functionality until the attacker navigates away or the session is terminated.
History

Wed, 31 Dec 2025 18:45:00 +0000

Type Values Removed Values Added
Description ZwiiCMS versions prior to 13.7.00 contain a denial-of-service vulnerability in multiple administrative endpoints due to improper authorization checks combined with flawed resource state management. When an authenticated low-privilege user requests an administrative page, the application returns "404 Not Found" as expected, but incorrectly acquires and associates a temporary lock on the targeted resource with the attacker session prior to authorization. This lock prevents other users, including administrators, from accessing the affected functionality until the attacker navigates away or the session is terminated.
Title ZwiiCMS < 13.7.00 Lock Persistence Authenticated DoS Against Administrative Pages
Weaknesses CWE-667
CWE-863
References
Metrics cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2025-12-31T18:39:35.214Z

Reserved: 2025-04-15T19:15:22.606Z

Link: CVE-2025-34467

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2025-12-31T19:15:43.753

Modified: 2025-12-31T19:15:43.753

Link: CVE-2025-34467

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.