File Upload vulnerability in JIZHICMS v.2.5, allows remote attacker to execute arbitrary code via a crafted file uploaded and downloaded to the download_url parameter in the app/admin/exts/ directory.
References
Link Resource
https://github.com/Cherry-toto/jizhicms/issues/91 Exploit Issue Tracking
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2023-12-28T00:00:00

Updated: 2023-12-28T05:38:17.398224

Reserved: 2023-12-11T00:00:00


Link: CVE-2023-50692

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2023-12-28T06:15:44.400

Modified: 2024-01-04T20:25:53.587


Link: CVE-2023-50692

JSON object: View

cve-icon Redhat Information

No data.

CWE