CVE-2022-37700

HIGH

Zentao Demo15 - Directory Traversal via getconfig Mode Parameter

Title source: llm
STIX 2.1

Description

Zentao Demo15 is vulnerable to Directory Traversal. The impact is: obtain sensitive information (remote). The component is: URL : view-source:https://demo15.zentao.pm/user-login.html/zentao/index.php?mode=getconfig.

References (3)

Core 3

Scores

CVSS v3 7.5
EPSS 0.0269
EPSS Percentile 84.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-22
Status published
Products (1)
easycorp/zentao 15.0
Published Sep 19, 2022
Tracked Since Feb 18, 2026