CVE-2024-7924
Zzcms
CVE-2024-7924 is a critical path traversal vulnerability found in ZZCMS 2023, potentially allowing attackers to access sensitive files. This flaw exists in the /I/list.php
file and can be exploited remotely by manipulating the skin
argument. With an SVRS of 68, while not critical, it indicates a serious risk requiring prompt attention. Attackers can leverage this vulnerability to navigate directories outside the intended path, potentially exposing sensitive data, configuration files, or even executing arbitrary code in some scenarios. The public availability of exploit code further increases the risk of active exploitation. Addressing CVE-2024-7924 is crucial to prevent unauthorized file access and maintain the security of the ZZCMS installation. Ignoring this vulnerability could lead to significant security breaches and compromise the entire system.
Indicators of Compromise
Exploits
News
Social Media
Affected Software
References
CWE Details
CVE Radar
Real-time CVE Intelligence & Vulnerability Management Platform
CVE Radar provides comprehensive vulnerability intelligence by monitoring CVE databases, security advisories, and threat feeds. Get instant updates on new vulnerabilities, exploit details, and mitigation strategies specific to your assets.