Aller au contenu

Fiche vulnérabilité

CVE-2025-2637 : faille moyenne jizhicms jizhicms (CVSS 5.3)

Description

A vulnerability, which was classified as problematic, has been found in JIZHICMS up to 1.7.0. Affected by this issue is some unknown functionality of the file /user/userinfo.html of the component Account Profile Page. The manipulation of the argument jifen leads to improper authorization. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

En bref

Sévérité
Moyenne (CVSS 5.3)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Exploitation active
Non signalée par la CISA
Publication
23 mars 2025
Dernière mise à jour
17 juin 2026

Produits concernés

  • jizhicms jizhicms

Références

Rechercher une autre vulnérabilité dans la base CVE