CyberRota Analysis
This is a critical severity vulnerability with a CVSS score of 9.1. See the original NVD description below for full technical details.
CVE
CVE-2025-25785
Severity
CRITICAL
CVSS
9.1
EPSS
0.42%
Original NVD Description
JizhiCMS v2.5.4 was discovered to contain a Server-Side Request Forgery (SSRF) via the component \c\PluginsController.php. This vulnerability allows attackers to perform an intranet scan via a crafted request.
Related CVEs
Other vulnerabilities affecting the same vendor(s)