A vulnerability, which was classified as critical, was found in ZhiCms 4.0. Affected is the function index of the file app/manage/controller/setcontroller.php. The manipulation of the argument sitename leads to code injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-255270 is the identifier assigned to this vulnerability.
Metrics
Affected Vendors & Products
References
History
Mon, 19 May 2025 13:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Zhicms
Zhicms zhicms |
|
CPEs | cpe:2.3:a:zhicms:zhicms:4.0:*:*:*:*:*:*:* | |
Vendors & Products |
Zhicms
Zhicms zhicms |

Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2024-08-01T18:56:22.610Z
Reserved: 2024-02-29T14:12:42.926Z
Link: CVE-2024-2016

Updated: 2024-08-01T18:56:22.610Z

Status : Analyzed
Published: 2024-03-21T02:52:26.760
Modified: 2025-05-19T13:09:09.277
Link: CVE-2024-2016

No data.