First published: Thu Sep 22 2022(Updated: )
ZZCMS 2022 was discovered to contain a full path disclosure vulnerability via the page /admin/index.PHP? _server.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Zzcms Zzcms | =2022 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-40444 is a full path disclosure vulnerability in ZZCMS 2022.
The vulnerability can disclose sensitive information about the file system path on the server, potentially aiding an attacker in identifying further vulnerabilities or crafting targeted attacks.
The severity of CVE-2022-40444 is medium, with a CVSS score of 5.3.
To fix the vulnerability, it is recommended to apply the latest patch or update provided by the vendor of ZZCMS 2022. Additionally, make sure to follow secure coding practices and properly handle error messages to avoid exposing sensitive information.
You can find more information about CVE-2022-40444 on the official GitHub page of ZZCMS.