Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-5359 | JizhiCMS v2.5.4 was discovered to contain a Server-Side Request Forgery (SSRF) via the component \c\PluginsController.php. This vulnerability allows attackers to perform an intranet scan via a crafted request. |
| Link | Providers |
|---|---|
| http://jizhicms.com |
|
| https://www.jizhicms.cn/ |
|
Thu, 10 Apr 2025 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Jizhicms
Jizhicms jizhicms |
|
| CPEs | cpe:2.3:a:jizhicms:jizhicms:2.5.4:*:*:*:*:*:*:* | |
| Vendors & Products |
Jizhicms
Jizhicms jizhicms |
Wed, 05 Mar 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-918 | |
| Metrics |
cvssV3_1
|
Wed, 26 Feb 2025 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | JizhiCMS v2.5.4 was discovered to contain a Server-Side Request Forgery (SSRF) via the component \c\PluginsController.php. This vulnerability allows attackers to perform an intranet scan via a crafted request. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-03-05T14:48:07.543Z
Reserved: 2025-02-07T00:00:00.000Z
Link: CVE-2025-25785
Updated: 2025-03-05T14:48:02.780Z
Status : Analyzed
Published: 2025-02-26T15:15:26.720
Modified: 2025-04-10T17:38:56.293
Link: CVE-2025-25785
No data.
OpenCVE Enrichment
No data.
EUVD