
CVE-2020-37117 jizhiCMS 1.6.7 contains a file download vulnerability in the admin plugins update endpoint that allows authenticated administrators to download arbitrary files. Attac… https://www.cve.org/CVERecord?id=CVE-2020-37117
Post summary
A file download vulnerability (CVE-2020-37117) in jizhiCMS 1.6.7 allows authenticated administrators to download arbitrary files via the admin plugins update endpoint.
