Jizhicms v2.5.4 contains a critical Server-Side Request Forgery (SSRF) vulnerability affecting its User Evaluation, Message, and Comment modules, allowing attackers to make unauthorized requests from the affected server. The vulnerability carries a CVSS score of 9.1 (Critical) with a network-based attack vector that requires no authentication or user interaction, making it easily exploitable by remote attackers. The SSRF enables high-impact confidentiality and integrity compromises, as attackers could access internal resources and potentially modify data or systems accessible from the vulnerable server. There is currently no evidence of active exploitation in the wild, with the vulnerability absent from the CISA Known Exploited Vulnerabilities (KEV) catalog and showing minimal community attention. The FAUCET Risk Score of 43.0 and low EPSS score suggest limited real-world exploitation activity to date, though organizations running Jizhicms v2.5.4 should prioritize patching given the critical severity rating.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.5.4CPE matchmatch criteria | cpe:2.3:a:jizhicms:jizhicms:2.5.4:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.