PT-2025-12504 · Jizhicms · Jizhicms

H3Rmesk1T

·

Published

2025-03-23

·

Updated

2025-04-02

·

CVE-2025-2637

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions JIZHICMS version 1.7.0
Description A vulnerability has been found in JIZHICMS, affecting some unknown functionality of the file /user/userinfo.html of the component Account Profile Page. The manipulation of the jifen argument leads to improper authorization. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
Recommendations For JIZHICMS version 1.7.0, consider disabling the functionality related to the jifen argument in the /user/userinfo.html file until a patch is available. Restrict access to the Account Profile Page to minimize the risk of exploitation. Avoid using the jifen argument in the affected component until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Authorization

Incorrect Privilege Assignment

Weakness Enumeration

Related Identifiers

CVE-2025-2637

Affected Products

Jizhicms