Zlt2000

Microservices-platform

5 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.5%
  • Veröffentlicht 16.09.2026 13:16:45
  • Zuletzt bearbeitet 24.09.2026 20:48:01

zlt2000 microservices-platform through 6.0.0 contains an authorization bypass vulnerability in the file-center module DELETE /files/{id} endpoint that performs no ownership validation. Authenticated attackers can enumerate file identifiers via GET /f...

Exploit
  • EPSS 0.37%
  • Veröffentlicht 16.09.2026 13:16:44
  • Zuletzt bearbeitet 18.09.2026 18:18:11

zlt2000 microservices-platform through 6.0.0 contains an authorization bypass vulnerability in the search-center service that allows authenticated attackers to read any Elasticsearch index by specifying the index name in POST /search/{indexName} and ...

Exploit
  • EPSS 0.85%
  • Veröffentlicht 16.09.2026 13:16:43
  • Zuletzt bearbeitet 16.09.2026 19:47:01

zlt2000 microservices-platform through 6.0.0 contains a missing authorization vulnerability where the zlt.security.auth.urlPermission.enable flag defaults to false, disabling all permission checks after authentication. Authenticated users with no rol...

Exploit
  • EPSS 0.43%
  • Veröffentlicht 16.09.2026 13:16:43
  • Zuletzt bearbeitet 21.09.2026 18:17:15

zlt2000 microservices-platform through 6.0.0 contains an unverified password change vulnerability in the PUT /users/password endpoint that allows authenticated users to change any account password by omitting the current password check. Attackers can...

Exploit
  • EPSS 0.3%
  • Veröffentlicht 11.08.2025 10:15:33
  • Zuletzt bearbeitet 29.04.2026 01:00:01

A vulnerability was identified in zlt2000 microservices-platform up to 6.0.0. Affected by this vulnerability is the function Upload of the file zlt-business/file-center/src/main/java/com/central/file/controller/FileController.java. The manipulation l...