CVE-2018-7434: Zzcms

Medium severity, CVSS 5.3. EPSS: 2.3% chance of exploitation in the next 30 days.

zzcms 8.2 allows remote attackers to discover the full path via a direct request to 3/qq_connect2.0/API/class/ErrorCase.class.php or 3/ucenter_api/code/friend.php.

Affected products

  • Zzcms Zzcms: version 8.2 only

Published 2018-02-24. Last modified 2026-06-17.