CVE-2023-34878: High severity UJCMS UJCMS vulnerability
Published Jun 14, 2023
·Updated
An issue was discovered in Ujcms v6.0.2 allows attackers to gain sensitive information via the dir parameter to /api/backend/core/web-file-html/download-zip.
Affected Software
1 affected component
UJCMS UJCMS=6.0.2
Event History
Jun 14, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-34878?
The severity of CVE-2023-34878 is rated as high with a CVSS score of 7.5.
2
How can I mitigate CVE-2023-34878 vulnerability?
To mitigate CVE-2023-34878, users should update to a patched version of Ujcms that addresses the issue.
3
What software version is affected by CVE-2023-34878?
The Ujcms version 6.0.2 is affected by CVE-2023-34878.
4
How does CVE-2023-34878 impact security?
CVE-2023-34878 allows attackers to gain sensitive information through the dir parameter in Ujcms v6.0.2.
5
Where can I find more information about CVE-2023-34878?
For more information about CVE-2023-34878, refer to the GitHub link: https://github.com/ujcms/ujcms/issues/6.