github.com
https://github.com/liong007/ZZCMS/issues/1 CVE-2022-40443
MEDIUMNuclei
ZZCMS 2022 - Path Information Disclosure
Record summary
CVE-2022-40443 has a selected CVSS score of 5.3 (medium); EIP currently links 1 Nuclei template.
Description
An absolute path traversal vulnerability in ZZCMS 2022 allows attackers to obtain sensitive information via a crafted GET request sent to /one/siteinfo.php.
Description source: CVE List
Exploitation context
Available material
- Nuclei templates
- 1
CISA SSVC decision
ExploitationNone
AutomatableYes
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated May 27, 2025 · Source: CVE List
Nuclei templates
1ProjectDiscoveryLOWZZCMS 2022 - Path Information DisclosureCVSS 5.3
An absolute path traversal vulnerability in ZZCMS 2022 allows attackers to obtain sensitive information via a crafted GET request.
Impact
An attacker can gain sensitive information about the server's file system.
Remediation
Apply the vendor-supplied patch or upgrade to a non-vulnerable version.
WeaknessesCWE-22
Authorsritikchaddha
Template tagscvecve22zzcmsdisclosurevuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CPE: cpe:2.3:a:zzcms:zzcms:2022:*:*:*:*:*:*:*
Shodan: html:"zzcms"
FOFA: body="zzcms"
Source: ProjectDiscovery
References
2nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2022-40443