LMSZAI Installation Page Exposure Scanner

This scanner checks for publicly accessible LMSZAI installation endpoints, allowing attackers to view sensitive setup configurations and paths.

Short Info


Level

High

Single Scan

Single Scan

Can be used by

Asset Owner

Estimated Time

10 seconds

Time Interval

27 days 23 hours

Scan only one

URL

Toolbox

LMSZAI is a Learning Management System used by educational institutions and corporate training programs to deliver online courses, manage assessments, and track learner progress. It offers robust features for content distribution and customization, making it a popular choice for digital learning environments.

The vulnerability involves exposure of the installation page, which occurs when the system is deployed without proper access restrictions. This allows unauthorized users to access the setup interface, revealing critical configuration details such as database paths, server settings, and system architecture.

Technically, the issue arises from misconfigured web server permissions or failure to remove or restrict the installation directory after deployment. Attackers can directly access the /install or /setup endpoint, bypassing authentication and viewing sensitive information that aids in further exploitation.

If exploited, this exposure can lead to information leakage, enabling attackers to map the infrastructure, identify weak points, and potentially execute more severe attacks like remote code execution or data breaches. The CVSS score of 8.0 reflects the high risk of unauthorized access to system configurations.

Get started to protecting your digital assets