First published: Thu Aug 03 2023(Updated: )
An arbitrary file download vulnerability in the /c/PluginsController.php component of jizhi CMS 1.9.5 allows attackers to execute arbitrary code via downloading a crafted plugin.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Jizhicms Jizhicms | =1.9.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-38948 is an arbitrary file download vulnerability in the /c/PluginsController.php component of jizhi CMS 1.9.5.
CVE-2023-38948 allows attackers to execute arbitrary code by downloading a crafted plugin.
The severity of CVE-2023-38948 is high with a score of 7.2.
The affected software version of CVE-2023-38948 is Jizhicms 1.9.5.
To fix CVE-2023-38948, it is recommended to update jizhi CMS to a version that has addressed the vulnerability.