PoC Index

CVE-2023-2927

CRITICAL 9.8EPSS 0.9%

A vulnerability was found in JIZHICMS 2.4.5. It has been classified as critical. Affected is the function index of the file TemplateController.php. The manipulation of the argument webapi leads to server-side request forgery. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-230082 is the identifier assigned to this vulnerability. Es wurde eine kritische Schwachstelle in JIZHICMS 2.4.5 ausgemacht. Es geht dabei um die Funktion index der Datei TemplateController.php. Mittels Manipulieren des Arguments webapi mit unbekannten Daten kann eine server-side request forgery-Schwachstelle ausgenutzt werden. Der Angriff kann über das Netzwerk passieren. Der Exploit steht zur öffentlichen Verfügung.

CVSS v3.1
9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v3.1
6.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
CVSS v2.0
6.5 MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
EPSS
0.87% chance of exploitation in the next 30 days, 56th percentile
Published
2023-05-27
Updated
2024-08-02

Proof-of-concept exploits (1)

References

Related