Skip to main content
HIGH

CVE-2022-27055

CVSS v3

7.5

HIGH

EPSS Score

1.6 %

exploit probability, as of 2026-09-25

CISA KEV

No

known exploited

Exploitation

—

SSVC status

Description

ecjia-daojia 1.38.1-20210202629 is vulnerable to information leakage via content/apps/installer/classes/Helper.php. When the web program is installed, a new environment file is created, and the database information is recorded, including the database record password. NOTE: the vendor disputes this because the environment file is in the data directory, which is not intended for access by website visitors (only the statics directory can be accessed by website visitors)

Technical details

Published
2022-04-19

Frequently asked questions

What is CVE-2022-27055?

ecjia-daojia 1.38.1-20210202629 is vulnerable to information leakage via content/apps/installer/classes/Helper.php. When the web program is installed, a new environment file is created, and the database information is recorded, including the database record password. NOTE: the vendor disputes this because the environment file is in the data directory, which is not intended for access by website visitors (only the statics directory can be accessed by website visitors)

Is CVE-2022-27055 actively exploited?

Active exploitation of CVE-2022-27055 has not been confirmed. Its EPSS score was 1.6% on 2026-09-25, the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2022-27055?

CVE-2022-27055 has a CVSS v3 base score of 7.5 (HIGH severity).

Is CVE-2022-27055 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.

No credit card required · 500 free checks/month · Free API key