PT-2022-18430 · Tpcms+1 · Tpcms+1

Xrun

·

Published

2022-04-04

·

Updated

2022-04-12

·

CVE-2022-27442

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions TPCMS version 3.2
Description The issue allows attackers to access the ThinkPHP log directory, potentially obtaining sensitive information such as the administrator's user name and password.
Recommendations For TPCMS version 3.2, restrict access to the ThinkPHP log directory to minimize the risk of exploitation. Consider implementing additional security measures to protect sensitive information. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Insertion into Log File

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-27442

Affected Products

Tpcms
Thinkphp