NA

CVE-2023-38948

Published: 03/08/2023 Updated: 08/08/2023
CVSS v3 Base Score: 7.2 | Impact Score: 5.9 | Exploitability Score: 1.2
VMScore: 0

Vulnerability Summary

An arbitrary file download vulnerability in the /c/PluginsController.php component of jizhi CMS 1.9.5 allows malicious users to execute arbitrary code via downloading a crafted plugin.

Vulnerable Product Search on Vulmon Subscribe to Product

jizhicms jizhicms 1.9.5