PT-2025-49105 · Jizhicms · Jizhicms

·

CVE-2025-14012

·

Published

2025-12-04

·

Updated

2026-02-24

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions JIZHICMS versions up to 2.5.5
Description A flaw exists in JIZHICMS that could allow for SQL injection. The issue is located in the deleteAll, findAll, and delete functions within the /index.php/admins/Comment/deleteAll.html file of the Batch Delete Comments component. This issue can be exploited remotely. The details of the flaw have been publicly disclosed. The vendor was notified but did not respond.
Recommendations Versions prior to 2.5.5 should be updated.

Exploit

Fix

Special Elements Injection

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-14012

Affected Products

Jizhicms