CVE-2024-7925

MEDIUM

ZZCMS 2023 - Information Disclosure via eginfo.php phome Parameter

Title source: llm
STIX 2.1

Description

A vulnerability was found in ZZCMS 2023. It has been rated as problematic. This issue affects some unknown processing of the file 3/E_bak5.1/upload/eginfo.php. The manipulation of the argument phome with the input ShowPHPInfo leads to information disclosure. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

References (4)

Core 4
Core References
Third Party Advisory, VDB Entry vdb-entry technical-description
https://vuldb.com/?id.275111
Permissions Required, VDB Entry signature permissions-required
https://vuldb.com/?ctiid.275111
Third Party Advisory, VDB Entry third-party-advisory
https://vuldb.com/?submit.392121

Scores

CVSS v3 4.3
EPSS 0.0012
EPSS Percentile 30.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-200
Status published
Products (1)
zzcms/zzcms 2023
Published Aug 19, 2024
Tracked Since Feb 18, 2026