Filtered by vendor Zhicms
                        
                        Subscribe
                        
                        
                    
                    
                
                    Total
                    3 CVE
                
            | CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 | 
|---|---|---|---|---|---|
| CVE-2024-2016 | 1 Zhicms | 1 Zhicms | 2025-05-19 | 6.5 MEDIUM | 6.3 MEDIUM | 
| A vulnerability, which was classified as critical, was found in ZhiCms 4.0. Affected is the function index of the file app/manage/controller/setcontroller.php. The manipulation of the argument sitename leads to code injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-255270 is the identifier assigned to this vulnerability. | |||||
| CVE-2024-2015 | 1 Zhicms | 1 Zhicms | 2025-05-19 | 6.5 MEDIUM | 6.3 MEDIUM | 
| A vulnerability, which was classified as critical, has been found in ZhiCms 4.0. This issue affects the function getindexdata of the file app/index/controller/mcontroller.php. The manipulation of the argument key leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-255269 was assigned to this vulnerability. | |||||
| CVE-2024-0603 | 1 Zhicms | 1 Zhicms | 2024-11-21 | 7.5 HIGH | 7.3 HIGH | 
| A vulnerability classified as critical has been found in ZhiCms up to 4.0. This affects an unknown part of the file app/plug/controller/giftcontroller.php. The manipulation of the argument mylike leads to deserialization. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-250839. | |||||
