ZFile v4.1.1 was discovered to contain an arbitrary file upload vulnerability via the component /file/upload/1.