First published: Thu Jun 09 2022(Updated: )
Jizhicms v2.2.5 was discovered to contain a Server-Side Request Forgery (SSRF) vulnerability via the Index function in app/admin/c/PluginsController.php.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Jizhicms Jizhicms | =2.2.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-31393 is a Server-Side Request Forgery (SSRF) vulnerability in Jizhicms v2.2.5.
CVE-2022-31393 has a severity rating of 9.1 (critical).
CVE-2022-31393 allows for SSRF attacks via the Index function in app/admin/c/PluginsController.php in Jizhicms v2.2.5.
To fix CVE-2022-31393 in Jizhicms v2.2.5, update to a version that includes the necessary security patches.
You can find more information about CVE-2022-31393 at the following reference: [https://github.com/Cherry-toto/jizhicms/issues/76](https://github.com/Cherry-toto/jizhicms/issues/76)