Metrics
Affected Vendors & Products
Fri, 04 Apr 2025 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Fri, 04 Apr 2025 06:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A vulnerability has been found in JFinal CMS up to 5.2.4 and classified as problematic. Affected by this vulnerability is the function engine.getTemplate of the file /readTemplate. The manipulation of the argument template leads to path traversal. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The real existence of this vulnerability is still doubted at the moment. The vendor explains that this is not a bug but a feature. | |
Title | JFinal CMS readTemplate engine.getTemplate path traversal | |
Weaknesses | CWE-22 | |
References |
| |
Metrics |
cvssV2_0
|

Status: PUBLISHED
Assigner: VulDB
Published: 2025-04-04T06:00:07.892Z
Updated: 2025-04-04T14:39:38.606Z
Reserved: 2025-04-03T13:21:37.707Z
Link: CVE-2025-3214

Updated: 2025-04-04T14:39:33.322Z

Status : Awaiting Analysis
Published: 2025-04-04T06:15:41.740
Modified: 2025-04-07T14:18:15.560
Link: CVE-2025-3214

No data.