PT-2025-14855 · Jfinalcms · Jfinalcms

760046475

·

Published

2025-04-04

·

Updated

2025-04-04

·

CVE-2025-3214

CVSS v2.0

4.0

Medium

VectorAV:N/AC:L/Au:S/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions JFinal CMS versions up to 5.2.4
Description A vulnerability has been found in the function engine.getTemplate of the file /readTemplate, where the manipulation of the template argument leads to path traversal. The attack can be launched remotely. The real existence of this vulnerability is still doubted, with the vendor explaining it as a feature rather than a bug.
Recommendations For versions up to 5.2.4, as a temporary workaround, consider restricting access to the engine.getTemplate function to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2025-3214

Affected Products

Jfinalcms