A vulnerability, which was classified as problematic, has been found in JIZHICMS up to 1.7.0. Affected by this issue is some unknown functionality of the file /user/userinfo.html of the component Account Profile Page. The manipulation of the argument jifen leads to improper authorization. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
History

Wed, 02 Apr 2025 16:00:00 +0000

Type Values Removed Values Added
First Time appeared Jizhicms
Jizhicms jizhicms
Weaknesses NVD-CWE-noinfo
CPEs cpe:2.3:a:jizhicms:jizhicms:*:*:*:*:*:*:*:*
Vendors & Products Jizhicms
Jizhicms jizhicms

Mon, 24 Mar 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 23 Mar 2025 00:15:00 +0000

Type Values Removed Values Added
Description A vulnerability, which was classified as problematic, has been found in JIZHICMS up to 1.7.0. Affected by this issue is some unknown functionality of the file /user/userinfo.html of the component Account Profile Page. The manipulation of the argument jifen leads to improper authorization. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
Title JIZHICMS Account Profile Page userinfo.html improper authorization
Weaknesses CWE-266
CWE-285
References
Metrics cvssV2_0

{'score': 4, 'vector': 'AV:N/AC:L/Au:S/C:N/I:P/A:N'}

cvssV3_0

{'score': 4.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}

cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2025-03-24T13:59:38.144Z

Reserved: 2025-03-22T04:48:26.199Z

Link: CVE-2025-2637

cve-icon Vulnrichment

Updated: 2025-03-24T13:59:33.403Z

cve-icon NVD

Status : Analyzed

Published: 2025-03-23T00:15:26.223

Modified: 2025-04-02T15:37:24.170

Link: CVE-2025-2637

cve-icon Redhat

No data.