Impact
A remote SQL injection flaw exists in the orderField argument of the /api/system/sys/dept/page endpoint in zsadmin2025 ZS-Admin. By manipulating the orderField value an attacker can inject arbitrary SQL into the ORDER BY clause, potentially exposing or modifying database contents. The weakness is reflected by CWE-74 and CWE-89, with a CVSS score of 5.3 and an EPSS of less than 1%, indicating a moderate severity but low current exploitation probability.
Affected Systems
The vulnerability affects all releases of the zsadmin2025 ZS-Admin application up to commit b52e14536d59fda11e56e2536a1c32e82a38cead. The project follows a rolling release strategy, so exact affected versions cannot be listed. Users should verify if their deployment includes the identified commit or a later fix.
Risk and Exploitability
Although the EPSS score is low and the vulnerability is not listed in CISA's KEV catalog, the attack can be carried out remotely via HTTP requests. Public disclosures have been made and no vendor response has been received, so the risk remains present until a patch or mitigated configuration is applied.
OpenCVE Enrichment