PT-2021-16799 · Ucms · Ucms

Published

2021-07-23

·

Updated

2021-08-03

·

CVE-2021-25809

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions UCMS version 1.5.0
Description The issue is related to a physical path leakage via an error message returned by the adminchannelscache() function in top.php. This leakage occurs in the specified version of the software.
Recommendations For UCMS version 1.5.0, consider restricting access to the adminchannelscache() function in top.php to minimize the risk of exploitation until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Generation of Error Message Containing Sensitive Information

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-25809

Affected Products

Ucms