PT-2024-16163 · Zzcms · Zzcms

Lvzc

·

Published

2024-10-23

·

Updated

2024-10-30

·

CVE-2024-10290

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions ZZCMS version 2023
Description A problematic issue was found in ZZCMS, affecting an unknown part of the file 3/qq-connect2.0/API/com/inc.php, leading to information disclosure. The attack can be initiated remotely.
Recommendations For ZZCMS version 2023, restrict firewall access to the vulnerable file 3/qq-connect2.0/API/com/inc.php to minimize the risk of exploitation. Patch the software when a fix becomes available.

Exploit

Fix

Information Disclosure

Weakness Enumeration

Related Identifiers

CVE-2024-10290

Affected Products

Zzcms