Record summary

CVE-2023-41599 has a selected CVSS score of 5.3 (medium); EIP currently links 1 Nuclei template.

Description

An issue in the component /common/DownController.java of JFinalCMS v5.0.0 allows attackers to execute a directory traversal.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Jun 8, 2025 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationPoC
AutomatableYes
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Sep 25, 2024 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus
VulnCheckVersion data not supplied

Nuclei templates

1
ProjectDiscoveryMEDIUMJFinalCMS v5.0.0 - Directory TraversalCVSS 5.3

An issue in the component /common/DownController.java of JFinalCMS v5.0.0 allows attackers to execute a directory traversal.

Impact

Unauthenticated attackers can read arbitrary files from the server through path traversal in the filekey parameter, potentially exposing database credentials, application configuration, and sensitive CMS content.

Remediation

Update JFinalCMS to a version newer than 5.0.0 that validates and sanitizes file paths in DownController.java to prevent directory traversal attacks.

WeaknessesCWE-22
Authorspussycat0x
Template tagscvecve2023jrecmsvkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CPE: cpe:2.3:a:jfinalcms_project:jfinalcms:5.0.0:*:*:*:*:*:*:*
FOFA: body="content=\"JreCms"

Source: ProjectDiscovery

References

2