First published: Mon Aug 19 2024(Updated: )
A vulnerability was found in ZZCMS 2023. It has been rated as problematic. This issue affects some unknown processing of the file 3/E_bak5.1/upload/eginfo.php. The manipulation of the argument phome with the input ShowPHPInfo leads to information disclosure. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
Credit: cna@vuldb.com
Affected Software | Affected Version | How to fix |
---|---|---|
ZZCMS | =2023 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-7925 has been rated as problematic.
CVE-2024-7925 affects the ZZCMS version 2023.
CVE-2024-7925 involves information disclosure due to improper handling of the phome argument.
Mitigation for CVE-2024-7925 involves restricting access to the vulnerable file upload script.
The potential impacts of CVE-2024-7925 include unauthorized access to sensitive information.