Information Disclosure Vulnerability in ZZCMS 2023
CVE-2024-7925

7.5HIGH

Key Information:

Vendor

Zzcms

Status
Vendor
CVE Published:
19 August 2024

What is CVE-2024-7925?

A security flaw exists in the ZZCMS 2023 that pertains to the eginfo.php file, specifically related to the processing of the phome argument with input that reveals PHP information. This vulnerability can lead to unauthorized access to sensitive information and may be exploited remotely by attackers, thereby posing a potential risk to users and systems utilizing this CMS. As the vulnerability has been publicly disclosed, immediate attention is recommended to mitigate any potential risks associated with this exposure.

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

.