Description
Jizhicms v2.5.4 is vulnerable to Server-Side Request Forgery (SSRF) in User Evaluation, Message, and Comment modules.
Published: 2026-04-09
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Potential internal network disclosure via server‑side request forgery
Action: Patch
AI Analysis

Impact

Jizhicms version 2.5.4 contains a server‑side request forgery vulnerability within the User Evaluation, Message, and Comment modules. An attacker can craft input that forces the server to make arbitrary HTTP requests to internal or external resources, which may expose sensitive data, access internal services, or facilitate further attacks.

Affected Systems

The vulnerability affects the Jizhicms content management system, specifically version 2.5.4. No additional vendor or product details are provided.

Risk and Exploitability

The risk level is uncertain due to the lack of CVSS, EPSS, or KEV scores. The exploitability is high if the vulnerable application is exposed to untrusted users, as the SSRF can be triggered through normal user interactions. There is no official patch or workaround listed; mitigation relies on applying a newer version or restricting outbound requests.

Generated by OpenCVE AI on April 9, 2026 at 16:29 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Check the vendor’s website or GitHub for a patched version of Jizhicms, and upgrade if a fix is available.
  • If upgrading is not immediately possible, restrict outbound network traffic from the web server to limit its ability to reach internal resources, thereby mitigating the SSRF attack surface.

Generated by OpenCVE AI on April 9, 2026 at 16:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 10 Apr 2026 10:00:00 +0000

Type Values Removed Values Added
Title Server‑Side Request Forgery in User Evaluation, Message, and Comment Modules of Jizhicms v2.5.4
Weaknesses CWE-918

Fri, 10 Apr 2026 09:00:00 +0000

Type Values Removed Values Added
First Time appeared Cherry-toto
Cherry-toto jizhicms
Vendors & Products Cherry-toto
Cherry-toto jizhicms

Thu, 09 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Description Jizhicms v2.5.4 is vulnerable to Server-Side Request Forgery (SSRF) in User Evaluation, Message, and Comment modules.
References

Subscriptions

Cherry-toto Jizhicms
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-04-09T14:44:40.458Z

Reserved: 2025-06-16T00:00:00.000Z

Link: CVE-2025-50228

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-04-09T15:16:07.433

Modified: 2026-04-09T15:16:07.433

Link: CVE-2025-50228

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-10T09:33:16Z

Weaknesses