Skip to content

Critical Security Vulnerability: Remote Code Execution (RCE) #235

@nulledphx

Description

@nulledphx

I've found a critical vulnerability in zMenu that allows Remote Code Execution (RCE) via the /zm download command (Path Traversal/Arbitrary File Write).

I have a full Proof of Concept (video and exploit scripts) and would like to share it privately to help you fix it.

Please let me know how to send you the details (e.g. your Discord, Email, or enable Private Vulnerability Reporting on this repo).

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions