High severity8.8NVD Advisory· Published Feb 5, 2026· Updated Jun 17, 2026
CVE-2020-37117
CVE-2020-37117
Description
jizhiCMS 1.6.7 contains a file download vulnerability in the admin plugins update endpoint that allows authenticated administrators to download arbitrary files. Attackers can exploit the vulnerability by sending crafted POST requests with malicious filepath and download_url parameters to trigger unauthorized file downloads.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3Patches
Vulnerability mechanics
References
3- www.exploit-db.com/exploits/48361nvdExploitVDB Entry
- www.vulncheck.com/advisories/jizhicms-arbitrary-file-downloadnvdThird Party Advisory
- www.jizhicms.cnnvdProduct
News mentions
0No linked articles in our index yet.