8.8
CVSSv3

CVE-2023-50692

Published: 28/12/2023 Updated: 04/01/2024
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

File Upload vulnerability in JIZHICMS v.2.5, allows remote malicious user to execute arbitrary code via a crafted file uploaded and downloaded to the download_url parameter in the app/admin/exts/ directory.

Vulnerable Product Search on Vulmon Subscribe to Product

jizhicms jizhicms 2.5