CVE-2025-14836
Severity CVSS v4.0:
MEDIUM
Type:
CWE-312
Cleartext Storage of Sensitive Information
Publication date:
17/12/2025
Last modified:
18/12/2025
Description
A flaw has been found in ZZCMS 2025. Affected by this vulnerability is an unknown functionality of the file /reg/user_save.php of the component User Data Storage Module. This manipulation causes cleartext storage in a file or on disk. Remote exploitation of the attack is possible. The exploit has been published and may be used.
Impact
Base Score 4.0
5.10
Severity 4.0
MEDIUM
Base Score 3.x
2.70
Severity 3.x
LOW
Base Score 2.0
3.30
Severity 2.0
LOW



