← voltar
CVE-2020-37117

jizhiCMS 1.6.7 - Arbitrary File Download

CVSS 8.6 HIGHEPSS 0.7%CWE-434
jizhiCMS 1.6.7 contains a file download vulnerability in the admin plugins update endpoint that allows authenticated administrators to download arbitrary files. Attackers can exploit the vulnerability by sending crafted POST requests with malicious filepath and download_url parameters to trigger unauthorized file downloads.
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Produtos afetados
jizhiCMS · jizhiCMS

Quer saber se a sua infraestrutura está exposta a isto?

Falar com a TrueHacking →