PT-2025-49105 · Jizhicms · Jizhicms

Nobb

·

Published

2025-12-04

·

Updated

2026-02-24

·

CVE-2025-14012

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions JIZHICMS versions up to 2.5.5
Description A flaw exists in JIZHICMS that could allow for SQL injection. The issue is located in the deleteAll, findAll, and delete functions within the /index.php/admins/Comment/deleteAll.html file of the Batch Delete Comments component. This issue can be exploited remotely. The details of the flaw have been publicly disclosed. The vendor was notified but did not respond.
Recommendations Versions prior to 2.5.5 should be updated.

Exploit

Fix

Special Elements Injection

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2025-14012

Affected Products

Jizhicms