An arbitrary file download vulnerability in the /c/PluginsController.php component of jizhi CMS 1.9.5 allows attackers to execute arbitrary code via downloading a crafted plugin.
References
Link | Resource |
---|---|
https://gitee.com/CTF-hacker/pwn/issues/I7LI4E | Exploit Issue Tracking Third Party Advisory |
https://gitee.com/CTF-hacker/pwn/issues/I7LI4E | Exploit Issue Tracking Third Party Advisory |
Configurations
History
No history.
Information
Published : 2023-08-03 16:15
Updated : 2024-11-21 08:14
NVD link : CVE-2023-38948
Mitre link : CVE-2023-38948
CVE.ORG link : CVE-2023-38948
JSON object : View
Products Affected
jizhicms
- jizhicms
CWE
CWE-552
Files or Directories Accessible to External Parties