CVE-2022-27442
HIGHTpcms - Log Information Exposure
Title source: ruleDescription
TPCMS v3.2 allows attackers to access the ThinkPHP log directory and obtain sensitive information such as the administrator's user name and password.
Exploits (1)
Scores
CVSS v3
7.5
EPSS
0.0027
EPSS Percentile
49.9%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Details
CWE
CWE-532
Status
published
Products (1)
tpcms_project/tpcms
3.2
Published
Apr 04, 2022
Tracked Since
Feb 18, 2026