CVE-2025-3214

CVSS 3.1 Score 9.9 of 10 (high)

Details

Published Apr 4, 2025
Updated: Apr 7, 2025
CWE ID 434

Summary

CVE-2025-3214 is a newly identified vulnerability affecting JFinal CMS versions up to 5.2.4. The issue lies within the engine.getTemplate function of the readTemplate file, which is susceptible to path traversal when the template argument is manipulated. This vulnerability can be exploited remotely, and the exploit has been disclosed to the public. However, the authenticity of the vulnerability is currently under debate, as the vendor claims it to be a intended feature rather than a bug.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share