Denial of Service via deleteLocalFile in Zj1983 File Handler (java)
CVE-2025-1846 Published on March 3, 2025

zj1983 zz File ZfileAction.java deleteLocalFile denial of service
A vulnerability was found in zj1983 zz up to 2024-8. It has been declared as problematic. This vulnerability affects the function deleteLocalFile of the file src/main/java/com/futvan/z/system/zfile/ZfileAction.java of the component File Handler. The manipulation of the argument zids leads to denial of service. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

NVD

Timeline

Advisory disclosed

VulDB entry created

VulDB entry last update

Weakness Type

Improper Resource Shutdown or Release

The program does not release or incorrectly releases a resource before it is made available for re-use. When a resource is created or allocated, the developer is responsible for properly releasing the resource as well as accounting for all potential paths of expiration or invalidation, such as a set period of time or revocation.


Products Associated with CVE-2025-1846

Want to know whenever a new CVE is published for Zframeworks Zz? stack.watch will email you.

 

Affected Versions

zj1983 zz Version 2024-8 is affected by CVE-2025-1846

Exploit Probability

EPSS
0.16%
Percentile
35.98%

EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.