Medium
CVSS 5.0
Overview
index.php for Zorum 3.4 allows remote attackers to determine the full path of the web root via invalid parameter names, which reveals the path in a PHP error message.
index.php for Zorum 3.4 allows remote attackers to determine the full path of th...
index.php for Zorum 3.4 allows remote attackers to determine the full path of the web root via invalid parameter names, which reveals the path in a PHP error message.
This vulnerability is rated 🟡 MEDIUM.
Recommended actions: