LMSZAI Installation Page Exposure Scanner
This scanner checks for publicly accessible LMSZAI installation endpoints, allowing attackers to view sensitive setup configurations and paths.
Short Info
Level
Single Scan
Single Scan
Can be used by
Asset Owner
Estimated Time
10 seconds
Time Interval
27 days 23 hours
Scan only one
URL
Toolbox
LMSZAI is a Learning Management System used by educational institutions and corporate training programs to deliver online courses, manage assessments, and track learner progress. It offers robust features for content distribution and customization, making it a popular choice for digital learning environments.
The vulnerability involves exposure of the installation page, which occurs when the system is deployed without proper access restrictions. This allows unauthorized users to access the setup interface, revealing critical configuration details such as database paths, server settings, and system architecture.
Technically, the issue arises from misconfigured web server permissions or failure to remove or restrict the installation directory after deployment. Attackers can directly access the /install or /setup endpoint, bypassing authentication and viewing sensitive information that aids in further exploitation.
If exploited, this exposure can lead to information leakage, enabling attackers to map the infrastructure, identify weak points, and potentially execute more severe attacks like remote code execution or data breaches. The CVSS score of 8.0 reflects the high risk of unauthorized access to system configurations.