PublicCMS V4.0.202204.a and below contains an information leak via the component /views/directive/sys/SysConfigDataDirective.java.
References
Link | Resource |
---|---|
https://github.com/sanluan/PublicCMS/commit/d8d7626cf51e4968fb384e1637a3c0c9921f33e9 | Patch Third Party Advisory |
https://github.com/JinYiTong/CVE-Req/blob/main/publiccms/publiccms.md | Exploit Third Party Advisory |
Configurations
Information
Published : 2022-06-03 14:15
Updated : 2022-06-13 12:15
NVD link : CVE-2022-29784
Mitre link : CVE-2022-29784
JSON object : View
CWE
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor
Products Affected
publiccms
- publiccms