← Back

CVE-2024-44820

nvd nist
Published: Sep 4, 2024Modified: Jun 17, 2026

JSON object

Loading...
6.1
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Exploitability: 2.8 / Impact: 2.7
Source: NVD

Description

A sensitive information disclosure vulnerability exists in ZZCMS v.2023 and before within the eginfo.php file located at /3/E_bak5.1/upload/. When accessed with the query parameter phome=ShowPHPInfo, the application executes the phpinfo() function, which exposes detailed information about the PHP environment, including server configuration, loaded modules, and environment variables.

Affected (1)

Products: Zzcms: Zzcms
1 product
Zzcms
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Up to 2023

Timeline

No history available yet.