CVE-2025-3214
Last modified
CVE-2025-3214 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale. A vulnerability has been found in JFinal CMS up to 5.2.4 and classified as problematic. Affected by this vulnerability is the function engine.getTemplate of the file /readTemplate. EPSS estimates a 0.43% chance of exploitation in the next 30 days.
Description
A vulnerability has been found in JFinal CMS up to 5.2.4 and classified as problematic. Affected by this vulnerability is the function engine.getTemplate of the file /readTemplate. The manipulation of the argument template leads to path traversal. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The real existence of this vulnerability is still doubted at the moment. The vendor explains that this is not a bug but a feature.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2025-3214?
How severe is CVE-2025-3214?
How do I fix CVE-2025-3214?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-32134Improper Neutralization of Input During Web Page Generation …5.9
- CVE-2025-32135Improper Neutralization of Input During Web Page Generation …5.9
- CVE-2025-32136Improper Neutralization of Input During Web Page Generation …5.9
- CVE-2025-32137Relative Path Traversal vulnerability in Cristián Lávaque s2…4.9
- CVE-2025-32138Improper Restriction of XML External Entity Reference vulner…6.6
- CVE-2025-32139Improper Neutralization of Input During Web Page Generation …5.9
- CVE-2025-32140Unrestricted Upload of File with Dangerous Type vulnerabilit…9.9
- CVE-2025-32141Improper Control of Filename for Include/Require Statement i…8.8
- CVE-2025-32142Improper Control of Filename for Include/Require Statement i…8.8
- CVE-2025-32143Deserialization of Untrusted Data vulnerability in PickPlugi…8.8
- CVE-2025-32144Deserialization of Untrusted Data vulnerability in PickPlugi…8.8
- CVE-2025-32145Deserialization of Untrusted Data vulnerability in magepeopl…8.8
Are you affected by CVE-2025-3214?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
