CVE-2020-37117
jizhiCMS 1.6.7 - Arbitrary File Download
Vexday Risk Score
21Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 8.6EPSS 0.7%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
05 Feb 2026Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
jizhiCMS 1.6.7 contains a file download vulnerability in the admin plugins update endpoint that allows authenticated administrators to download arbitrary files. Attackers can exploit the vulnerability by sending crafted POST requests with malicious filepath and download_url parameters to trigger unauthorized file downloads.
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Affected products
jizhiCMS · jizhiCMS