Juzaweb CMS是Juzaweb个人开发者的一个基于 Laravel 框架和 Web 平台开发的内容管理系统。 juzaweb CMS 3.4.2及之前版本存在安全漏洞,该漏洞源于文件/admin-cp/theme/editor/default访问控制不当。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2025-5421 | 6.3 MEDIUM | juzaweb CMS Plugin Editor Page editor access control |
| CVE-2025-5423 | 6.3 MEDIUM | juzaweb CMS General Setting Page general access control |
| CVE-2025-5424 | 6.3 MEDIUM | juzaweb CMS Media Page media access control |
| CVE-2025-5426 | 6.3 MEDIUM | juzaweb CMS Menu Page menus access control |
| CVE-2025-5427 | 6.3 MEDIUM | juzaweb CMS Permalinks Page permalinks access control |
| CVE-2025-5428 | 6.3 MEDIUM | juzaweb CMS Error Logs Page log-viewer access control |
| CVE-2025-5429 | 6.3 MEDIUM | juzaweb CMS Plugins Page install access control |
| CVE-2025-5422 | 4.3 MEDIUM | juzaweb CMS Email Logs Page email access control |
| CVE-2025-5420 | 3.5 LOW | juzaweb CMS Profile Page upload cross site scripting |
No comments yet