Record summary

CVE-2022-40443 has a selected CVSS score of 5.3 (medium); EIP currently links 1 Nuclei template.

Description

An absolute path traversal vulnerability in ZZCMS 2022 allows attackers to obtain sensitive information via a crafted GET request sent to /one/siteinfo.php.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationNone
AutomatableYes
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated May 27, 2025 · Source: CVE List

Nuclei templates

1
ProjectDiscoveryLOWZZCMS 2022 - Path Information DisclosureCVSS 5.3

An absolute path traversal vulnerability in ZZCMS 2022 allows attackers to obtain sensitive information via a crafted GET request.

Impact

An attacker can gain sensitive information about the server's file system.

Remediation

Apply the vendor-supplied patch or upgrade to a non-vulnerable version.

WeaknessesCWE-22
Authorsritikchaddha
Template tagscvecve22zzcmsdisclosurevuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CPE: cpe:2.3:a:zzcms:zzcms:2022:*:*:*:*:*:*:*
Shodan: html:"zzcms"
FOFA: body="zzcms"

Source: ProjectDiscovery

References

2