Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-43011

Опубликовано: 16 авг. 2024
Источник: nvd
CVSS3: 4.9
EPSS Низкий

Описание

An arbitrary file deletion vulnerability exists in the admin/del.php file at line 62 in ZZCMS 2023 and earlier. Due to insufficient validation and sanitization of user input for file paths, an attacker can exploit this vulnerability by using directory traversal techniques to delete arbitrary files on the server. This can lead to the deletion of critical files, potentially disrupting the normal operation of the system.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:zzcms:zzcms:*:*:*:*:*:*:*:*
Версия до 2023 (включая)

EPSS

Процентиль: 62%
0.00433
Низкий

4.9 Medium

CVSS3

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 4.9
github
больше 1 года назад

An arbitrary file deletion vulnerability exists in the admin/del.php file at line 62 in ZZCMS 2023 and earlier. Due to insufficient validation and sanitization of user input for file paths, an attacker can exploit this vulnerability by using directory traversal techniques to delete arbitrary files on the server. This can lead to the deletion of critical files, potentially disrupting the normal operation of the system.

EPSS

Процентиль: 62%
0.00433
Низкий

4.9 Medium

CVSS3

Дефекты

CWE-22