Junglewise Threat Intelligence

CVE-2025-70397: jizhicms SQL injection in Article and Extmolds deleteAll functions

CVE-2025-70397 · Severity: high · CVSS 7.2 · Published 2026-02-17

Executive brief

jizhicms, a content management system, is vulnerable to a security flaw that could allow an attacker to manipulate the website's database. By exploiting this weakness in the content deletion features, an authorized user could potentially view, modify, or delete sensitive information they should not have access to. This could lead to a total loss of data integrity or unauthorized disclosure of site information.

Technical details

A SQL injection vulnerability exists in jizhicms version 2.5.6 within the 'Article/deleteAll' and 'Extmolds/deleteAll' functions. The vulnerability is rooted in the improper neutralization of the 'data' parameter, which is used in SQL commands without sufficient sanitization. An attacker with high-level administrative privileges can exploit this over a network to execute arbitrary SQL queries. This can result in full unauthorized access to the underlying database, including the ability to extract, modify, or delete data. A proof-of-concept has been identified in third-party advisories.

Affected products

  • jizhicms jizhicms 2.5.6

Timeline

  • 2026-02-15: disclosed: Initial third-party advisory and exploit published
  • 2026-02-17: advisory: CVE-2025-70397 published by NVD/MITRE

References