CVE-2025-3214
CVSS 3.1 Score 9.9 of 10 (high)
Details
Published Apr 4, 2025
Updated: Apr 7, 2025
CWE ID 434
Summary
CVE-2025-3214 is a newly identified vulnerability affecting JFinal CMS versions up to 5.2.4. The issue lies within the engine.getTemplate function of the readTemplate file, which is susceptible to path traversal when the template argument is manipulated. This vulnerability can be exploited remotely, and the exploit has been disclosed to the public. However, the authenticity of the vulnerability is currently under debate, as the vendor claims it to be a intended feature rather than a bug.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Vendors
- WordPress