CVE-2025-59872 PUBLISHED

HCL ZIE for Web is affetced by an Unrestricted File Upload vulnerability,

Assigner: HCL
Reserved: 22.09.2025 Published: 17.06.2026 Updated: 17.06.2026

HCL ZIE for Web is affetced by an Unrestricted File Upload vulnerability, If the server is configured to execute code, then it may be possible to obtain command execution on the server by uploading a file known as a web shell, which allows you to execute arbitrary code or operating system commands. For this attack to be successful, the file needs to be uploaded inside the Webroot, and the server must be configured to execute the code

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
CVSS Score: 4.3

Product Status

Vendor HCL Software
Product ZIE
Versions Default: unaffected
  • Version 16.0 is affected

References

Problem Types

  • CWE-209 Generation of Error Message Containing Sensitive Information CWE