A vulnerability has been found in JIZHICMS up to 1.7.0 and classified as problematic. This vulnerability affects unknown code of the file /user/release.html of the component Article Handler. The manipulation leads to improper authorization. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
History

Fri, 28 Mar 2025 20:00:00 +0000

Type Values Removed Values Added
First Time appeared Jizhicms
Jizhicms jizhicms
Weaknesses NVD-CWE-noinfo
CPEs cpe:2.3:a:jizhicms:jizhicms:*:*:*:*:*:*:*:*
Vendors & Products Jizhicms
Jizhicms jizhicms

Mon, 24 Mar 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 23 Mar 2025 03:00:00 +0000

Type Values Removed Values Added
Description A vulnerability has been found in JIZHICMS up to 1.7.0 and classified as problematic. This vulnerability affects unknown code of the file /user/release.html of the component Article Handler. The manipulation leads to improper authorization. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
Title JIZHICMS Article release.html improper authorization
Weaknesses CWE-266
CWE-285
References
Metrics cvssV2_0

{'score': 4, 'vector': 'AV:N/AC:L/Au:S/C:N/I:P/A:N'}

cvssV3_0

{'score': 4.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}

cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2025-03-24T14:25:12.626Z

Reserved: 2025-03-22T04:48:34.667Z

Link: CVE-2025-2639

cve-icon Vulnrichment

Updated: 2025-03-24T14:23:51.393Z

cve-icon NVD

Status : Analyzed

Published: 2025-03-23T03:15:11.807

Modified: 2025-03-28T19:33:14.553

Link: CVE-2025-2639

cve-icon Redhat

No data.