JizhiCMS Server-Side Request Forgery Vulnerability

Vulnerability

A Server-Side Request Forgery (SSRF) vulnerability has been identified in JizhiCMS version 2.5.4, specifically within the PluginsController.php component. This vulnerability allows attackers to conduct intranet scans by sending crafted requests.

Impact

Exploitation of this vulnerability could lead to unauthorized access to internal services or resources, allowing an attacker to perform reconnaissance on the internal network.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
1.0
impact
0.0
exploitability
7.6
remediation
0.0
relevance
0.0
threat
0.0
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.