First published: Thu Jan 04 2024(Updated: )
Jizhicms v2.5 was discovered to contain an arbitrary file download vulnerability via the component /admin/c/PluginsController.php.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Jizhicms | =2.5.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-51154 has been classified as a high severity vulnerability due to its potential for arbitrary file downloads.
To remediate CVE-2023-51154, it is recommended to update Jizhicms to the latest version that contains a patch for this vulnerability.
CVE-2023-51154 affects Jizhicms version 2.5.0.
Yes, CVE-2023-51154 can be exploited remotely, allowing attackers to download arbitrary files from the server.
The vulnerability CVE-2023-51154 is found in the /admin/c/PluginsController.php component of Jizhicms.