CVE-2025-65897
zdhweb is a data collection, processing, monitoring, scheduling, and management platform. In zdhweb thru 5.6.17, insufficient validation of file upload paths in the application allows an authenticated user to write arbitrary files to the server file system, potentially overwriting existing files and leading to privilege escalation or remote code execution.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://github.com/zhaoyachao/zdhweb/issues/40, https://github.com/zhaoyachao/zdhweb/commit/b2423378a8bf83f159f19ce4e14eac71c939793a, https://github.com/zhaoyachao/zdhweb/pull/39, https://github.com/zhaoyachao/zdhweb
