An arbitrary file upload vulnerability in the component \c\TemplateController.php of Jizhicms v2.5.4 allows attackers to execute arbitrary code via uploading a crafted Zip file.
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.
Link | Tags |
---|---|
http://jizhicms.com | not applicable |
https://www.jizhicms.cn/ | product |
https://github.com/Ka7arotto/JizhiCms/blob/main/jizhicms.md | vendor advisory exploit |