VYPR
Medium severity6.3NVD Advisory· Published Mar 21, 2024· Updated Jun 17, 2026

CVE-2024-2016

CVE-2024-2016

Description

A vulnerability, which was classified as critical, was found in ZhiCms 4.0. Affected is the function index of the file app/manage/controller/setcontroller.php. The manipulation of the argument sitename leads to code injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-255270 is the identifier assigned to this vulnerability.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • ZhiCms/ZhiCms2 versions
    cpe:2.3:a:zhicms:zhicms:4.0:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:zhicms:zhicms:4.0:*:*:*:*:*:*:*
    • (no CPE)range: =4.0
  • ZhiCms/ZhiCmsdescription

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.