nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2020-37117 CVE-2020-37117
HIGH
jizhiCMS 1.6.7 - Arbitrary File Download
Record summary
CVE-2020-37117 has a selected CVSS score of 8.6 (high); EIP currently links 1 catalogued exploit.
Description
jizhiCMS 1.6.7 contains a file download vulnerability in the admin plugins update endpoint that allows authenticated administrators to download arbitrary files. Attackers can exploit the vulnerability by sending crafted POST requests with malicious filepath and download_url parameters to trigger unauthorized file downloads.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
CISA SSVC decision
ExploitationPoC
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Feb 6, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
jizhiCMSBrowse jizhiCMS / jizhiCMS | CVE List | 1.6.7 | affected |
Proofs of concept
1Catalogued exploits
ExploitDBjizhi CMS 1.6.7 - Arbitrary File DownloadExploitDB exploitby jizhicmsNot analyzed1 file
References
4ExploitDB-48361exploit
https://www.exploit-db.com/exploits/48361 Official Vendor Homepageproduct
https://www.jizhicms.cn/ VulnCheck Advisory: jizhiCMS 1.6.7 - Arbitrary File DownloadThird-party advisory
https://www.vulncheck.com/advisories/jizhicms-arbitrary-file-download