CVE-2018-8969 An issue was discovered in zzcms 82 user/licence_savephp allows remote attackers to delete arbitrary files via directory traversal sequences in the oldimg parameter in an action=modify request This can be leveraged for database access by deleting installlock authentication complexity vector NONE LOW NETWORK confidentiality integrity availability