← back
CVE-2024-7926

ZZCMS about_edit.php path traversal

CVSS 6.9 MEDIUMEPSS 0.9%CWE-22
Vexday Risk Score
13Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 6.9EPSS 0.9%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
19 Aug 2024Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
A vulnerability classified as critical has been found in ZZCMS 2023. Affected is an unknown function of the file /admin/about_edit.php?action=modify. The manipulation of the argument skin leads to path traversal. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N
Affected products
n/a · ZZCMS