A vulnerability, which was classified as critical, was found in ZhiCms 4.0. Affected is the function index of the file app/manage/controller/setcontroller.php. The manipulation of the argument sitename leads to code injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-255270 is the identifier assigned to this vulnerability.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: VulDB
Published: 2024-02-29T21:31:04.756Z
Updated: 2024-08-01T18:56:22.610Z
Reserved: 2024-02-29T14:12:42.926Z
Link: CVE-2024-2016
Vulnrichment
Updated: 2024-08-01T18:56:22.610Z
NVD
Status : Awaiting Analysis
Published: 2024-03-21T02:52:26.760
Modified: 2024-06-04T19:19:12.807
Link: CVE-2024-2016
Redhat
No data.