First published: Sun Mar 23 2025(Updated: )
A vulnerability, which was classified as problematic, has been found in JIZHICMS up to 1.7.0. Affected by this issue is some unknown functionality of the file /user/userinfo.html of the component Account Profile Page. The manipulation of the argument jifen leads to improper authorization. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
Credit: cna@vuldb.com
Affected Software | Affected Version | How to fix |
---|---|---|
Jizhicms | <=1.7.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-2637 is classified as a problematic vulnerability.
To fix CVE-2025-2637, upgrade JIZHICMS to a version later than 1.7.0.
CVE-2025-2637 affects the Account Profile Page functionality in JIZHICMS up to version 1.7.0.
CVE-2025-2637 may allow for improper authorization attacks through manipulation of the jifen argument.
CVE-2025-2637 is notable but specific to certain versions of JIZHICMS, making its commonality limited to affected users.