ZwiiCMS versions prior to 13.7.00 contain a denial-of-service vulnerability in multiple administrative endpoints due to improper authorization checks combined with flawed resource state management. When an authenticated low-privilege user requests an administrative page, the application returns "404 Not Found" as expected, but incorrectly acquires and associates a temporary lock on the targeted resource with the attacker session prior to authorization. This lock prevents other users, including administrators, from accessing the affected functionality until the attacker navigates away or the session is terminated.
History

Mon, 05 Jan 2026 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 05 Jan 2026 10:45:00 +0000

Type Values Removed Values Added
First Time appeared Zwiicms
Zwiicms zwiicms
Vendors & Products Zwiicms
Zwiicms zwiicms

Wed, 31 Dec 2025 18:45:00 +0000

Type Values Removed Values Added
Description ZwiiCMS versions prior to 13.7.00 contain a denial-of-service vulnerability in multiple administrative endpoints due to improper authorization checks combined with flawed resource state management. When an authenticated low-privilege user requests an administrative page, the application returns "404 Not Found" as expected, but incorrectly acquires and associates a temporary lock on the targeted resource with the attacker session prior to authorization. This lock prevents other users, including administrators, from accessing the affected functionality until the attacker navigates away or the session is terminated.
Title ZwiiCMS < 13.7.00 Lock Persistence Authenticated DoS Against Administrative Pages
Weaknesses CWE-667
CWE-863
References
Metrics cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published: 2025-12-31T18:39:35.214Z

Updated: 2026-01-05T14:23:51.016Z

Reserved: 2025-04-15T19:15:22.606Z

Link: CVE-2025-34467

cve-icon Vulnrichment

Updated: 2026-01-05T14:23:45.991Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-12-31T19:15:43.753

Modified: 2025-12-31T20:42:15.637

Link: CVE-2025-34467

cve-icon Redhat

No data.