CVE-2024-8694 is a path traversal vulnerability affecting JFinalCMS up to version 20240903, specifically within the update function of the /admin/template/update file in the com.cms.controller.admin.TemplateController component. This flaw allows a remote attacker with high privileges to manipulate the fileName argument, leading to potential data modification or denial of service. While the exploit has been publicly disclosed, there is no evidence of active exploitation, and it has received minimal community or media attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 20240903CPE matchmatch criteria | cpe:2.3:a:heyewei:jfinalcms:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.0 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.