CVE-2020-37117: Jizhicms
High severity, CVSS 8.8. EPSS: 0.8% chance of exploitation in the next 30 days.
jizhiCMS 1.6.7 contains a file download vulnerability in the admin plugins update endpoint that allows authenticated administrators to download arbitrary files. Attackers can exploit the vulnerability by sending crafted POST requests with malicious filepath and download_url parameters to trigger unauthorized file downloads.
Affected products
- Jizhicms Jizhicms: version 1.6.7 only
Published 2026-02-05. Last modified 2026-06-17.