ShadowTrackr

Search the CVE vulnerability database

Look up vulnerabilities by software, product or CVE number.

1 result for “CVE-2020-37117”

CVEPublishedCVSSShadowTrackr CVSSSummary
CVE:
CVE-2020-37117
Published
2026-02-05
CVSS:
8.6
ShadowTrackr CVSS:
6.1
Summary:
jizhiCMS 1.6.7 contains a file download vulnerability in the admin plugins update endpoint that allows authenticated administrators to download arbitrary files. Attackers can exploit the vulnerability by sending crafted POST requests with malicious filepath and download_url parameters to trigger unauthorized file downloads.