CVE-2020-37117
HIGH SEVERITYCVSS Score & Metrics
Base Score
8.8 / 10
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Vulnerability Description
jizhiCMS 1.6.7 contains a file download vulnerability in the admin plugins update endpoint that allows authenticated administrators to download arbitrary files. Attackers can exploit the vulnerability by sending crafted POST requests with malicious filepath and download_url parameters to trigger unauthorized file downloads.
Vulnerability Details
Published Date
Last Modified
CWE ID
CWE-434
Source
NVD
Vendor
jizhiCMS
Product
jizhiCMS
Discussion (0)
Add Comment
No comments yet. Be the first!