Sensitive Information Disclosure in ZZCMS by ZZCMS
CVE-2024-44820

6.1MEDIUM

Key Information:

Vendor
Zzcms
Status
Zzcms
Vendor
CVE Published:
4 September 2024

Summary

A vulnerability exists in ZZCMS versions 2023 and earlier, specifically in the eginfo.php file located at /3/E_bak5.1/upload/. When an attacker accesses this file with the query parameter phome=ShowPHPInfo, it triggers the execution of the phpinfo() function. This behavior exposes sensitive information about the PHP environment, including extensive details regarding server configuration, loaded modules, and various environment variables, potentially aiding malicious users in compromising the application.

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

.