{
    "data_version": "4.0",
    "data_type": "CVE",
    "data_format": "MITRE",
    "CVE_data_meta": {
        "ID": "CVE-2024-8694",
        "ASSIGNER": "cna@vuldb.com",
        "STATE": "PUBLIC"
    },
    "description": {
        "description_data": [
            {
                "lang": "eng",
                "value": "A vulnerability, which was classified as problematic, was found in JFinalCMS up to 20240903. This affects the function update of the file /admin/template/update of the component com.cms.controller.admin.TemplateController. The manipulation of the argument fileName leads to path traversal. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used."
            },
            {
                "lang": "deu",
                "value": "Es wurde eine problematische Schwachstelle in JFinalCMS bis 20240903 gefunden. Es geht dabei um die Funktion update der Datei /admin/template/update der Komponente com.cms.controller.admin.TemplateController. Dank der Manipulation des Arguments fileName mit unbekannten Daten kann eine path traversal-Schwachstelle ausgenutzt werden. Der Angriff kann \u00fcber das Netzwerk passieren. Der Exploit steht zur \u00f6ffentlichen Verf\u00fcgung."
            }
        ]
    },
    "problemtype": {
        "problemtype_data": [
            {
                "description": [
                    {
                        "lang": "eng",
                        "value": "CWE-22 Path Traversal",
                        "cweId": "CWE-22"
                    }
                ]
            }
        ]
    },
    "affects": {
        "vendor": {
            "vendor_data": [
                {
                    "vendor_name": "n/a",
                    "product": {
                        "product_data": [
                            {
                                "product_name": "JFinalCMS",
                                "version": {
                                    "version_data": [
                                        {
                                            "version_affected": "=",
                                            "version_value": "20240903"
                                        }
                                    ]
                                }
                            }
                        ]
                    }
                }
            ]
        }
    },
    "references": {
        "reference_data": [
            {
                "url": "https://vuldb.com/?id.277167",
                "refsource": "MISC",
                "name": "https://vuldb.com/?id.277167"
            },
            {
                "url": "https://vuldb.com/?ctiid.277167",
                "refsource": "MISC",
                "name": "https://vuldb.com/?ctiid.277167"
            },
            {
                "url": "https://vuldb.com/?submit.401858",
                "refsource": "MISC",
                "name": "https://vuldb.com/?submit.401858"
            },
            {
                "url": "https://gitee.com/heyewei/JFinalcms/issues/IAOKSQ",
                "refsource": "MISC",
                "name": "https://gitee.com/heyewei/JFinalcms/issues/IAOKSQ"
            },
            {
                "url": "https://github.com/wave-to/SomeCms/blob/main/JFinalCMS.md",
                "refsource": "MISC",
                "name": "https://github.com/wave-to/SomeCms/blob/main/JFinalCMS.md"
            }
        ]
    },
    "credits": [
        {
            "lang": "en",
            "value": "wavesky (VulDB User)"
        }
    ],
    "impact": {
        "cvss": [
            {
                "version": "3.1",
                "baseScore": 3.8,
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L",
                "baseSeverity": "LOW"
            },
            {
                "version": "3.0",
                "baseScore": 3.8,
                "vectorString": "CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L",
                "baseSeverity": "LOW"
            },
            {
                "version": "2.0",
                "baseScore": 4.7,
                "vectorString": "AV:N/AC:L/Au:M/C:N/I:P/A:P"
            }
        ]
    }
}