Impact
The flaw in WuzhiCMS up to 4.1.0 occurs when the Attachment API endpoint at /index.php?m=attachment&f=index&v=upload is accessed with crafted parameters. The endpoint fails to enforce proper permission checks (CWE‑284) and returns a list of image metadata, revealing filenames, paths, and potentially other confidential data, which corresponds to CWE‑200 Information Exposure. This leads to unauthorized disclosure of content stored by the CMS.
Affected Systems
Affected systems include installations of WuzhiCMS version 4.1.0 and earlier, as the vulnerability was fixed in later releases. The documentation shows affected products packaged under the WuzhiCMS CMS distribution. No specific sub‑version or build details are listed beyond the general “up to 4.1.0” statement.
Risk and Exploitability
The CVSS score of 6.9 indicates medium‑to‑high severity, and the EPSS score of < 1% suggests a very low probability of exploitation in the near term, although the published exploit indicates that attackers have demonstrated the flaw. The vulnerability can be exploited remotely without needing user credentials; the only requirement is being able to send an HTTP request to the API. Because it is not listed in the CISA KEV catalog, mitigation remains reliant on vendor updates or network controls.
OpenCVE Enrichment