Show filters
3 Total Results
Displaying 1-3 of 3
Sort by:
Attacker Value
Unknown
CVE-2023-2927
Disclosure Date: May 27, 2023 (last updated October 08, 2023)
A vulnerability was found in JIZHICMS 2.4.5. It has been classified as critical. Affected is the function index of the file TemplateController.php. The manipulation of the argument webapi leads to server-side request forgery. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-230082 is the identifier assigned to this vulnerability.
0
Attacker Value
Unknown
CVE-2023-27235
Disclosure Date: March 15, 2023 (last updated February 24, 2025)
An arbitrary file upload vulnerability in the \admin\c\CommonController.php component of Jizhicms v2.4.5 allows attackers to execute arbitrary code via a crafted phtml file.
0
Attacker Value
Unknown
CVE-2023-27234
Disclosure Date: March 15, 2023 (last updated February 24, 2025)
A Cross-Site Request Forgery (CSRF) in /Sys/index.html of Jizhicms v2.4.5 allows attackers to arbitrarily make configuration changes within the application.
0