PT-2025-8709 · Jizhicms · Jizhicms

Published

2025-02-26

·

Updated

2025-03-08

·

CVE-2025-25784

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Jizhicms version 2.5.4
Description The issue is related to an arbitrary file upload vulnerability in the TemplateController.php component. This vulnerability allows attackers to execute arbitrary code by uploading a crafted Zip file.
Recommendations For Jizhicms version 2.5.4, consider restricting access to the TemplateController.php component until a patch is available. As a temporary workaround, avoid using the file upload functionality in the affected component to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-25784

Affected Products

Jizhicms