CVE-2023-51154
CVSS 3.1 Score 9.8 of 10 (high)
Details
Published Jan 4, 2024
Updated: Jan 10, 2024
Summary
CVE-2023-51154 is a newly disclosed vulnerability affecting Jizhicms version 2.5. This issue grants an attacker the ability to download arbitrary files by manipulating requests to the /admin/c/PluginsController.php component. An unauthenticated attacker can potentially exploit this vulnerability to obtain sensitive information or execute malicious code. Successful exploitation could lead to significant security risks and potential data breaches. It is strongly recommended that users upgrade to the latest version of Jizhicms to mitigate this threat.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share