← volver
CVE-2020-37117

jizhiCMS 1.6.7 - Arbitrary File Download

CVSS 8.6 HIGHEPSS 0.7%CWE-434
Vexday Risk Score
21Bajo
Decisión SSVC (CISA)
Track
Sin señal de explotación → monitorear
CVSS 8.6EPSS 0.7%KEV nãoPoC Nuclei Metasploit Patch
Ciclo de vida
05 feb 2026Publicada en NVD
Recomendación: Monitorear — sin señal de explotación por ahora.
jizhiCMS 1.6.7 contains a file download vulnerability in the admin plugins update endpoint that allows authenticated administrators to download arbitrary files. Attackers can exploit the vulnerability by sending crafted POST requests with malicious filepath and download_url parameters to trigger unauthorized file downloads.
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Productos afectados
jizhiCMS · jizhiCMS