Vulnerability Description
TPCMS v3.2 allows attackers to access the ThinkPHP log directory and obtain sensitive information such as the administrator's user name and password.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Tpcms Project | Tpcms | 3.2 |
Related Weaknesses (CWE)
References
- https://gitee.com/happy_source/tpcms/issues/I3YNWYExploitIssue TrackingThird Party Advisory
- https://gitee.com/happy_source/tpcms/issues/I3YNWYExploitIssue TrackingThird Party Advisory
FAQ
What is CVE-2022-27442?
CVE-2022-27442 is a vulnerability with a CVSS score of 7.5 (HIGH). TPCMS v3.2 allows attackers to access the ThinkPHP log directory and obtain sensitive information such as the administrator's user name and password.
How severe is CVE-2022-27442?
CVE-2022-27442 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-27442?
Check the references section above for vendor advisories and patch information. Affected products include: Tpcms Project Tpcms.