CVE-2025-2638
CVSS 3.1 Score 5.3 of 10 (medium)
Details
Published Mar 23, 2025
Updated: Apr 2, 2025
CWE ID 285
CWE ID 266
Summary
CVE-2025-2638 is a newly disclosed vulnerability affecting JIZHICMS up to version 1.7.0. The issue lies in the Article Handler component's /user/release.html file, where improper authorization can be granted through manipulation of the argument ishot with an input of 1. This vulnerability permits remote attacks and has been publicly disclosed, making it a significant security concern.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- JIZHICMS
Affected Vendors
- Jizhicms