CVE-2018-7434: Zzcms
Medium severity, CVSS 5.3. EPSS: 2.3% chance of exploitation in the next 30 days.
zzcms 8.2 allows remote attackers to discover the full path via a direct request to 3/qq_connect2.0/API/class/ErrorCase.class.php or 3/ucenter_api/code/friend.php.
Affected products
- Zzcms Zzcms: version 8.2 only
Published 2018-02-24. Last modified 2026-06-17.