Metrics
Affected Vendors & Products
Thu, 05 Jun 2025 20:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Heyewei
Heyewei jfinalcms |
|
CPEs | cpe:2.3:a:heyewei:jfinalcms:*:*:*:*:*:*:*:* | |
Vendors & Products |
Heyewei
Heyewei jfinalcms |
Thu, 12 Sep 2024 17:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Jfinalcms Project
Jfinalcms Project jfinalcms |
|
CPEs | cpe:2.3:a:jfinalcms_project:jfinalcms:*:*:*:*:*:*:*:* | |
Vendors & Products |
Jfinalcms Project
Jfinalcms Project jfinalcms |
|
Metrics |
ssvc
|
Wed, 11 Sep 2024 23:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A vulnerability was found in JFinalCMS up to 20240903. It has been classified as problematic. This affects the function update of the file /admin/template/update of the component com.cms.util.TemplateUtils. The manipulation of the argument fileName leads to path traversal. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. | |
Title | JFinalCMS com.cms.util.TemplateUtils update path traversal | |
Weaknesses | CWE-22 | |
References |
| |
Metrics |
cvssV2_0
|

Status: PUBLISHED
Assigner: VulDB
Published: 2024-09-11T23:31:06.227Z
Updated: 2024-09-12T16:40:49.801Z
Reserved: 2024-09-11T16:28:21.627Z
Link: CVE-2024-8706

Updated: 2024-09-12T16:40:34.990Z

Status : Analyzed
Published: 2024-09-12T00:15:02.363
Modified: 2025-06-05T20:07:09.180
Link: CVE-2024-8706

No data.