Back to CVE List

CVE-2020-37117

HIGH SEVERITY

CVSS Score & Metrics

Base Score
8.8 / 10
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Vulnerability Description

jizhiCMS 1.6.7 contains a file download vulnerability in the admin plugins update endpoint that allows authenticated administrators to download arbitrary files. Attackers can exploit the vulnerability by sending crafted POST requests with malicious filepath and download_url parameters to trigger unauthorized file downloads.

Vulnerability Details

Published Date
Last Modified
CWE ID
CWE-434
Source
NVD
Vendor
jizhiCMS
Product
jizhiCMS

External References

Discussion (0)

Add Comment

No comments yet. Be the first!