Impact
Jizhicms version 2.5.4 contains a server‑side request forgery vulnerability within the User Evaluation, Message, and Comment modules. An attacker can craft input that forces the server to make arbitrary HTTP requests to internal or external resources, which may expose sensitive data, access internal services, or facilitate further attacks.
Affected Systems
The vulnerability affects the Jizhicms content management system, specifically version 2.5.4. No additional vendor or product details are provided.
Risk and Exploitability
The risk level is uncertain due to the lack of CVSS, EPSS, or KEV scores. The exploitability is high if the vulnerable application is exposed to untrusted users, as the SSRF can be triggered through normal user interactions. There is no official patch or workaround listed; mitigation relies on applying a newer version or restricting outbound requests.
OpenCVE Enrichment