Description
A vulnerability was found in JFinalCMS up to 20240903. It has been classified as problematic. This affects the function update of the file /admin/template/update of the component com.cms.util.TemplateUtils. The manipulation of the argument fileName leads to path traversal. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
Published: 2024-09-11
Score: 5.3 Medium
EPSS: 1.1% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2024-49358 A vulnerability was found in JFinalCMS up to 20240903. It has been classified as problematic. This affects the function update of the file /admin/template/update of the component com.cms.util.TemplateUtils. The manipulation of the argument fileName leads to path traversal. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
History

Thu, 05 Jun 2025 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Heyewei
Heyewei jfinalcms
CPEs cpe:2.3:a:heyewei:jfinalcms:*:*:*:*:*:*:*:*
Vendors & Products Heyewei
Heyewei jfinalcms

Thu, 12 Sep 2024 17:30:00 +0000

Type Values Removed Values Added
First Time appeared Jfinalcms Project
Jfinalcms Project jfinalcms
CPEs cpe:2.3:a:jfinalcms_project:jfinalcms:*:*:*:*:*:*:*:*
Vendors & Products Jfinalcms Project
Jfinalcms Project jfinalcms
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 11 Sep 2024 23:45:00 +0000

Type Values Removed Values Added
Description A vulnerability was found in JFinalCMS up to 20240903. It has been classified as problematic. This affects the function update of the file /admin/template/update of the component com.cms.util.TemplateUtils. The manipulation of the argument fileName leads to path traversal. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
Title JFinalCMS com.cms.util.TemplateUtils update path traversal
Weaknesses CWE-22
References
Metrics cvssV2_0

{'score': 4, 'vector': 'AV:N/AC:L/Au:S/C:P/I:N/A:N'}

cvssV3_0

{'score': 4.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}

cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Heyewei Jfinalcms
Jfinalcms Project Jfinalcms
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2024-09-12T16:40:49.801Z

Reserved: 2024-09-11T16:28:21.627Z

Link: CVE-2024-8706

cve-icon Vulnrichment

Updated: 2024-09-12T16:40:34.990Z

cve-icon NVD

Status : Analyzed

Published: 2024-09-12T00:15:02.363

Modified: 2025-06-05T20:07:09.180

Link: CVE-2024-8706

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses