CVE-2025-59872 - CVE House
Back to Database
Status published Medium CVE-2025-59872

HCL ZIE for Web is affetced by an Unrestricted File Upload vulnerability,

Vulnerability Description

HCL ZIE for Web is affetced by an Unrestricted File Upload vulnerability, If the server is configured to execute code, then it may be possible to obtain command execution on the server by uploading a file known as a web shell, which allows you to execute arbitrary code or operating system commands. For this attack to be successful, the file needs to be uploaded inside the Webroot, and the server must be configured to execute the code

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-59872

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

HCL Software

View all reports →

Affected Software

ZIE
Vulnerable Versions:
16.0

Timeline

Official Publish: June 17th, 2026
Last Modified: June 17th, 2026
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Weaknesses (CWE)