An issue was discovered in Ujcms v6.0.2 allows attackers to gain sensitive information via the dir parameter to /api/backend/core/web-file-html/download-zip.
References
Link | Resource |
---|---|
https://github.com/ujcms/ujcms/issues/6 | Exploit Issue Tracking Vendor Advisory |
https://github.com/ujcms/ujcms/issues/6 | Exploit Issue Tracking Vendor Advisory |
Configurations
History
02 Jan 2025, 21:15
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-203 |
Information
Published : 2023-06-14 14:15
Updated : 2025-01-02 21:15
NVD link : CVE-2023-34878
Mitre link : CVE-2023-34878
CVE.ORG link : CVE-2023-34878
JSON object : View
Products Affected
ujcms
- ujcms
CWE