S4E just found a medium-severity finding from cookies without secure attribute security misconfiguration scanner
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Jan 21, 2025

CVE-2022-40443 Scanner

CVE-2022-40443 Scanner - Path Information Disclosure vulnerability in ZZCMS

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.7k
Times Used
continuous scan runs
5.5k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2022-40443
5.3
CVSSmedium
Exploitable remotely over the internet · no authentication required.

An absolute path traversal vulnerability in ZZCMS 2022 allows attackers to obtain sensitive information via a crafted GET request sent to /one/siteinfo.php.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
n/aby n/a
n/a
Updated Aug 22, 2026View on NVD →
Detail

ZZCMS is a widely used content management system designed for creating websites and managing content efficiently. It is commonly adopted by small to medium-sized businesses due to its ease of use and customizable features. ZZCMS provides tools for managing web pages, users, and other resources, making it suitable for a variety of industries.

The detected vulnerability is a Path Information Disclosure flaw in ZZCMS 2022. This vulnerability allows attackers to access sensitive server information via a specially crafted GET request. Improper validation and handling of user input in the `siteinfo.php` script contribute to this vulnerability.

Technically, the vulnerability exists in the `siteinfo.php` script, which fails to properly sanitize user input. Attackers can exploit this flaw by sending crafted requests to the affected endpoint, exposing absolute file paths and other sensitive details. These exposed paths can help attackers in further exploiting the system or launching targeted attacks.

Exploiting this vulnerability can lead to the disclosure of sensitive server information, including file system paths. This information could assist attackers in identifying additional vulnerabilities or preparing for more sophisticated attacks. Although the impact is limited to information disclosure, it still poses a risk to the overall security of the system.

REFERENCES

Solution Advice
  • Apply the vendor-supplied patch to address the vulnerability.
  • Update ZZCMS to a non-vulnerable version.
  • Ensure proper input validation and sanitization in all server-side scripts.
  • Restrict access to sensitive files and scripts through appropriate permissions.
  • Conduct regular security assessments to identify and address similar vulnerabilities.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.