First published: Wed Jun 14 2023(Updated: )
An issue was discovered in Ujcms v6.0.2 allows attackers to gain sensitive information via the dir parameter to /api/backend/core/web-file-html/download-zip.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
UJCMS Jspxcms | =6.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2023-34878 is rated as high with a CVSS score of 7.5.
To mitigate CVE-2023-34878, users should update to a patched version of Ujcms that addresses the issue.
The Ujcms version 6.0.2 is affected by CVE-2023-34878.
CVE-2023-34878 allows attackers to gain sensitive information through the dir parameter in Ujcms v6.0.2.
For more information about CVE-2023-34878, refer to the GitHub link: https://github.com/ujcms/ujcms/issues/6.