CVE-2024-0603

HIGH

zhicms < 4.0 - Deserialization via mylike Argument in Gift Controller

Title source: llm
STIX 2.1

Description

A vulnerability classified as critical has been found in ZhiCms up to 4.0. This affects an unknown part of the file app/plug/controller/giftcontroller.php. The manipulation of the argument mylike leads to deserialization. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-250839.

References (3)

Core 3
Core References
Third Party Advisory vdb-entry technical-description
https://vuldb.com/?id.250839
Third Party Advisory signature permissions-required
https://vuldb.com/?ctiid.250839
Broken Link broken-link exploit
https://note.zhaoj.in/share/n3QsNbORUR0e

Scores

CVSS v3 7.3
EPSS 0.0086
EPSS Percentile 53.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-502
Status published
Products (1)
zhicms/zhicms < 4.0
Published Jan 16, 2024
Tracked Since Feb 18, 2026