CVE-2022-27442

HIGH

Tpcms - Log Information Exposure

Title source: rule

Description

TPCMS v3.2 allows attackers to access the ThinkPHP log directory and obtain sensitive information such as the administrator's user name and password.

Exploits (1)

gitee 127 stars
by happy_source · phpwriteup
https://gitee.com/happy_source/tpcms/issues/I3YNWY

Scores

CVSS v3 7.5
EPSS 0.0027
EPSS Percentile 49.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-532
Status published
Products (1)
tpcms_project/tpcms 3.2
Published Apr 04, 2022
Tracked Since Feb 18, 2026