First published: Fri Apr 04 2025(Updated: )
A vulnerability has been found in JFinal CMS up to 5.2.4 and classified as problematic. Affected by this vulnerability is the function engine.getTemplate of the file /readTemplate. The manipulation of the argument template leads to path traversal. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The real existence of this vulnerability is still doubted at the moment. The vendor explains that this is not a bug but a feature.
Credit: cna@vuldb.com
Affected Software | Affected Version | How to fix |
---|---|---|
Final Draft | <=5.2.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-3214 has been classified as a problematic vulnerability due to its path traversal capability.
To fix CVE-2025-3214, it is recommended to upgrade JFinal CMS to version 5.2.5 or later.
CVE-2025-3214 is associated with remote path traversal attacks that exploit the engine.getTemplate function.
JFinal CMS versions up to and including 5.2.4 are affected by CVE-2025-3214.
Yes, CVE-2025-3214 can be exploited remotely by manipulating the argument template.