CVE-2024-8782 is a critical path traversal vulnerability affecting JFinalCMS up to version 1.0, specifically within the 'delete' function of the /admin/template/edit file. This flaw allows remote attackers to manipulate the 'name' argument, potentially leading to unauthorized access, modification, or deletion of files outside the intended directory. With a CVSS score of 9.8 (Critical) and a FAUCET Risk Score of 92/100, the vulnerability is easily exploitable over the network with low attack complexity and no user interaction required, resulting in high impacts to confidentiality, integrity, and availability. While not currently listed in CISA's KEV catalog, the exploit has been publicly disclosed, and community discussion is high, indicating significant awareness and potential for future exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.0CPE matchmatch criteria | cpe:2.3:a:heyewei:jfinalcms:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.