{
    "document": {
        "category": "csaf_base",
        "csaf_version": "2.0",
        "distribution": {
            "tlp": {
                "label": "WHITE"
            }
        },
        "lang": "en",
        "notes": [
            {
                "category": "legal_disclaimer",
                "text": "The Netherlands Cyber Security Center (henceforth: NCSC-NL) maintains this portal to enhance access to its information and vulnerabilities. The use of this information is subject to the following terms and conditions:\n\nThe vulnerabilities disclosed in this portal are gathered by NCSC-NL from a variety of open sources, which the user can retrieve from other platforms. NCSC-NL makes every reasonable effort to ensure that the content of this portal is kept up to date, and that it is accurate and complete. Nevertheless, NCSC-NL cannot entirely rule out the possibility of errors, and therefore cannot give any warranty in respect of its completeness, accuracy or real-time keeping up-to-date. NCSC-NL does not control nor guarantee the accuracy, relevance, timeliness or completeness of information obtained from these external sources. The vulnerabilities disclosed in this portal are intended solely for the convenience of professional parties to take appropriate measures to manage the risks posed to the cybersecurity. No rights can be derived from the information provided therein.\n\nNCSC-NL and the Kingdom of the Netherlands assume no legal liability or responsibility for any damage resulting from either the use or inability of use of the vulnerabilities disclosed in this portal. This includes damage resulting from the inaccuracy of incompleteness of the information contained in it.\nThe information on this page is subject to Dutch law. All disputes related to or arising from the use of this portal regarding the disclosure of vulnerabilities will be submitted to the competent court in The Hague. This choice of means also applies to the court in summary proceedings."
            }
        ],
        "publisher": {
            "category": "coordinator",
            "contact_details": "cert@ncsc.nl",
            "name": "National Cyber Security Centre",
            "namespace": "https://www.ncsc.nl/"
        },
        "title": "CVE-2025-70397",
        "tracking": {
            "current_release_date": "2026-03-28T14:39:37.273158Z",
            "generator": {
                "date": "2026-02-17T15:00:00Z",
                "engine": {
                    "name": "V.E.L.M.A",
                    "version": "1.7"
                }
            },
            "id": "CVE-2025-70397",
            "initial_release_date": "2026-02-17T16:27:01.052891Z",
            "revision_history": [
                {
                    "date": "2026-02-17T16:27:01.052891Z",
                    "number": "1",
                    "summary": "CVE created.| Source created.| CVE status created. (valid)| Description created for source.| References created (2)."
                },
                {
                    "date": "2026-02-17T16:27:07.479553Z",
                    "number": "2",
                    "summary": "NCSC Score created."
                },
                {
                    "date": "2026-02-17T16:51:09.113569Z",
                    "number": "3",
                    "summary": "Source created.| CVE status created. (valid)| Description created for source.| References created (2)."
                },
                {
                    "date": "2026-02-17T17:25:25.223969Z",
                    "number": "4",
                    "summary": "CVSS created.| CWES updated (1)."
                },
                {
                    "date": "2026-02-17T17:25:33.897253Z",
                    "number": "5",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-02-17T18:04:35.627415Z",
                    "number": "6",
                    "summary": "CVSS created.| CWES updated (1).| Unknown change."
                },
                {
                    "date": "2026-02-17T18:04:40.050151Z",
                    "number": "7",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-02-18T15:09:24.534577Z",
                    "number": "8",
                    "summary": "Source created.| CVE status created. (valid)| EPSS created."
                },
                {
                    "date": "2026-02-18T22:25:09.085672Z",
                    "number": "9",
                    "summary": "Products created (1).| Product Identifiers created (1).| Exploits created (1)."
                },
                {
                    "date": "2026-02-18T22:25:16.476470Z",
                    "number": "10",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-02-19T19:09:12.301973Z",
                    "number": "11",
                    "summary": "CVSS updated."
                },
                {
                    "date": "2026-02-19T19:09:14.904159Z",
                    "number": "12",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-02-19T19:25:31.363775Z",
                    "number": "13",
                    "summary": "CVSS updated."
                },
                {
                    "date": "2026-02-20T09:31:43.880902Z",
                    "number": "14",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-02-21T12:40:26.348619Z",
                    "number": "15",
                    "summary": "Source created.| CVE status created. (valid)| Description created for source.| CVSS created.| Products connected (44).| Products created (1).| References created (2)."
                },
                {
                    "date": "2026-02-21T12:40:39.131992Z",
                    "number": "16",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-03-19T20:10:44.641153Z",
                    "number": "17",
                    "summary": "Source connected.| CVE status created. (valid)| EPSS created."
                },
                {
                    "date": "2026-03-19T20:10:46.895161Z",
                    "number": "18",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-03-19T21:43:12.783654Z",
                    "number": "19",
                    "summary": "Source created.| CVE status created. (valid)| Description created for source.| CVSS created.| Products connected (1).| Product Identifiers created (1).| Exploits created (1).| References created (2).| CWES updated (1)."
                }
            ],
            "status": "interim",
            "version": "19"
        }
    },
    "product_tree": {
        "branches": [
            {
                "branches": [
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/2.3.3",
                                "product": {
                                    "name": "vers:unknown/2.3.3",
                                    "product_id": "CSAFPID-3463215"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/2.3.4",
                                "product": {
                                    "name": "vers:unknown/2.3.4",
                                    "product_id": "CSAFPID-3463216"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/2.3.5",
                                "product": {
                                    "name": "vers:unknown/2.3.5",
                                    "product_id": "CSAFPID-3463217"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/2.3.7",
                                "product": {
                                    "name": "vers:unknown/2.3.7",
                                    "product_id": "CSAFPID-3463218"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/2.3.8",
                                "product": {
                                    "name": "vers:unknown/2.3.8",
                                    "product_id": "CSAFPID-3463219"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/2.4",
                                "product": {
                                    "name": "vers:unknown/2.4",
                                    "product_id": "CSAFPID-3463220"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/2.4.0",
                                "product": {
                                    "name": "vers:unknown/2.4.0",
                                    "product_id": "CSAFPID-3463221"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/2.4.3",
                                "product": {
                                    "name": "vers:unknown/2.4.3",
                                    "product_id": "CSAFPID-3463222"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/2.4.7",
                                "product": {
                                    "name": "vers:unknown/2.4.7",
                                    "product_id": "CSAFPID-3627305"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/2.4.8",
                                "product": {
                                    "name": "vers:unknown/2.4.8",
                                    "product_id": "CSAFPID-3627306"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/2.4.9",
                                "product": {
                                    "name": "vers:unknown/2.4.9",
                                    "product_id": "CSAFPID-3627307"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/2.5.0",
                                "product": {
                                    "name": "vers:unknown/2.5.0",
                                    "product_id": "CSAFPID-3627308"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/2.5.1",
                                "product": {
                                    "name": "vers:unknown/2.5.1",
                                    "product_id": "CSAFPID-3627309",
                                    "product_identification_helper": {
                                        "cpe": "cpe:2.3:a:cherry-toto:jizhicms:-:*:*:*:*:*:*:*"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/2.5.2",
                                "product": {
                                    "name": "vers:unknown/2.5.2",
                                    "product_id": "CSAFPID-3796369"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/2.5.3",
                                "product": {
                                    "name": "vers:unknown/2.5.3",
                                    "product_id": "CSAFPID-3796370"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/2.5.4",
                                "product": {
                                    "name": "vers:unknown/2.5.4",
                                    "product_id": "CSAFPID-3796371"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/2.5.6",
                                "product": {
                                    "name": "vers:unknown/2.5.6",
                                    "product_id": "CSAFPID-5658542"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v1",
                                "product": {
                                    "name": "vers:unknown/v1",
                                    "product_id": "CSAFPID-3463223"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v1.4",
                                "product": {
                                    "name": "vers:unknown/v1.4",
                                    "product_id": "CSAFPID-3463224"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v1.5",
                                "product": {
                                    "name": "vers:unknown/v1.5",
                                    "product_id": "CSAFPID-3463225"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v1.5.1",
                                "product": {
                                    "name": "vers:unknown/v1.5.1",
                                    "product_id": "CSAFPID-3463226"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v1.5.2",
                                "product": {
                                    "name": "vers:unknown/v1.5.2",
                                    "product_id": "CSAFPID-3463227"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v1.6",
                                "product": {
                                    "name": "vers:unknown/v1.6",
                                    "product_id": "CSAFPID-3463228"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v1.6.1",
                                "product": {
                                    "name": "vers:unknown/v1.6.1",
                                    "product_id": "CSAFPID-3463229"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v1.6.2",
                                "product": {
                                    "name": "vers:unknown/v1.6.2",
                                    "product_id": "CSAFPID-3463230"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v1.6.3",
                                "product": {
                                    "name": "vers:unknown/v1.6.3",
                                    "product_id": "CSAFPID-3463231"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v1.6.4",
                                "product": {
                                    "name": "vers:unknown/v1.6.4",
                                    "product_id": "CSAFPID-3463232"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v1.6.5",
                                "product": {
                                    "name": "vers:unknown/v1.6.5",
                                    "product_id": "CSAFPID-3463233"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v1.6.6",
                                "product": {
                                    "name": "vers:unknown/v1.6.6",
                                    "product_id": "CSAFPID-3463234"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v1.6.7",
                                "product": {
                                    "name": "vers:unknown/v1.6.7",
                                    "product_id": "CSAFPID-3463235"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v1.7",
                                "product": {
                                    "name": "vers:unknown/v1.7",
                                    "product_id": "CSAFPID-3463236"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v1.7.1",
                                "product": {
                                    "name": "vers:unknown/v1.7.1",
                                    "product_id": "CSAFPID-3463237"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v1.8",
                                "product": {
                                    "name": "vers:unknown/v1.8",
                                    "product_id": "CSAFPID-3463238"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v1.8.1",
                                "product": {
                                    "name": "vers:unknown/v1.8.1",
                                    "product_id": "CSAFPID-3463239"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v1.9",
                                "product": {
                                    "name": "vers:unknown/v1.9",
                                    "product_id": "CSAFPID-3463240"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v1.9.1",
                                "product": {
                                    "name": "vers:unknown/v1.9.1",
                                    "product_id": "CSAFPID-3463241"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v1.9.2",
                                "product": {
                                    "name": "vers:unknown/v1.9.2",
                                    "product_id": "CSAFPID-3463242"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v1.9.3",
                                "product": {
                                    "name": "vers:unknown/v1.9.3",
                                    "product_id": "CSAFPID-3463243"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v1.9.4",
                                "product": {
                                    "name": "vers:unknown/v1.9.4",
                                    "product_id": "CSAFPID-3463244"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v1.9.5",
                                "product": {
                                    "name": "vers:unknown/v1.9.5",
                                    "product_id": "CSAFPID-3463245"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v1.9.x",
                                "product": {
                                    "name": "vers:unknown/v1.9.x",
                                    "product_id": "CSAFPID-3463246"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2.4.5",
                                "product": {
                                    "name": "vers:unknown/v2.4.5",
                                    "product_id": "CSAFPID-3463247"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2.5.3",
                                "product": {
                                    "name": "vers:unknown/v2.5.3",
                                    "product_id": "CSAFPID-3796372"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2.5.4",
                                "product": {
                                    "name": "vers:unknown/v2.5.4",
                                    "product_id": "CSAFPID-3796373"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2.5.5",
                                "product": {
                                    "name": "vers:unknown/v2.5.5",
                                    "product_id": "CSAFPID-5262780"
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "jizhicms"
                    }
                ],
                "category": "vendor",
                "name": "cherry-toto"
            },
            {
                "branches": [
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/2.5.6",
                                "product": {
                                    "name": "vers:unknown/2.5.6",
                                    "product_id": "CSAFPID-5630885",
                                    "product_identification_helper": {
                                        "cpe": "cpe:2.3:a:jizhicms:jizhicms:2.5.6:*:*:*:*:*:*:*"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "jizhicms"
                    }
                ],
                "category": "vendor",
                "name": "jizhicms"
            }
        ]
    },
    "vulnerabilities": [
        {
            "cve": "CVE-2025-70397",
            "cwe": {
                "id": "CWE-89",
                "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')"
            },
            "notes": [
                {
                    "category": "description",
                    "text": "jizhicms 2.5.6 is vulnerable to SQL Injection in Article/deleteAll and Extmolds/deleteAll via the data parameter.",
                    "title": "nvd - https://nvd.nist.gov/vuln/detail/CVE-2025-70397"
                },
                {
                    "category": "description",
                    "text": "jizhicms 2.5.6 is vulnerable to SQL Injection in Article/deleteAll and Extmolds/deleteAll via the data parameter.",
                    "title": "cveprojectv5 - https://www.cve.org/CVERecord?id=CVE-2025-70397"
                },
                {
                    "category": "description",
                    "text": "jizhicms 2.5.6 is vulnerable to SQL Injection in Article/deleteAll and Extmolds/deleteAll via the data parameter.",
                    "title": "osv - https://www.googleapis.com/download/storage/v1/b/osv-vulnerabilities/o/GIT%2FCVE-2025-70397.json?alt=media"
                },
                {
                    "category": "description",
                    "text": "jizhicms 2.5.6 is vulnerable to SQL Injection in Article/deleteAll and Extmolds/deleteAll via the data parameter.",
                    "title": "nvd - https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2025-70397"
                },
                {
                    "category": "other",
                    "text": "0.00035",
                    "title": "EPSS"
                },
                {
                    "category": "other",
                    "text": "3.3",
                    "title": "NCSC Score"
                },
                {
                    "category": "other",
                    "text": "The value of the most recent EPSS score, There is exploit data available from source Nvd, Is related to (a version of) an uncommon product",
                    "title": "NCSC Score top decreasing factors"
                }
            ],
            "product_status": {
                "known_affected": [
                    "CSAFPID-5630885",
                    "CSAFPID-3463215",
                    "CSAFPID-3463216",
                    "CSAFPID-3463217",
                    "CSAFPID-3463218",
                    "CSAFPID-3463219",
                    "CSAFPID-3463220",
                    "CSAFPID-3463221",
                    "CSAFPID-3463222",
                    "CSAFPID-3463223",
                    "CSAFPID-3463224",
                    "CSAFPID-3463225",
                    "CSAFPID-3463226",
                    "CSAFPID-3463227",
                    "CSAFPID-3463228",
                    "CSAFPID-3463229",
                    "CSAFPID-3463230",
                    "CSAFPID-3463231",
                    "CSAFPID-3463232",
                    "CSAFPID-3463233",
                    "CSAFPID-3463234",
                    "CSAFPID-3463235",
                    "CSAFPID-3463236",
                    "CSAFPID-3463237",
                    "CSAFPID-3463238",
                    "CSAFPID-3463239",
                    "CSAFPID-3463240",
                    "CSAFPID-3463241",
                    "CSAFPID-3463242",
                    "CSAFPID-3463243",
                    "CSAFPID-3463244",
                    "CSAFPID-3463245",
                    "CSAFPID-3463246",
                    "CSAFPID-3463247",
                    "CSAFPID-3627305",
                    "CSAFPID-3627306",
                    "CSAFPID-3627307",
                    "CSAFPID-3627308",
                    "CSAFPID-3627309",
                    "CSAFPID-3796369",
                    "CSAFPID-3796370",
                    "CSAFPID-3796371",
                    "CSAFPID-3796372",
                    "CSAFPID-3796373",
                    "CSAFPID-5262780",
                    "CSAFPID-5658542"
                ]
            },
            "references": [
                {
                    "category": "external",
                    "summary": "Source - nvd",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-70397"
                },
                {
                    "category": "external",
                    "summary": "Source raw - nvd",
                    "url": "https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2025-70397"
                },
                {
                    "category": "external",
                    "summary": "Source - cveprojectv5",
                    "url": "https://www.cve.org/CVERecord?id=CVE-2025-70397"
                },
                {
                    "category": "external",
                    "summary": "Source raw - cveprojectv5",
                    "url": "https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2025/70xxx/CVE-2025-70397.json"
                },
                {
                    "category": "external",
                    "summary": "Source - first",
                    "url": "https://api.first.org/data/v1/epss?cve=CVE-2025-70397"
                },
                {
                    "category": "external",
                    "summary": "Source raw - first",
                    "url": "https://api.first.org/data/v1/epss?limit=10000&offset=0"
                },
                {
                    "category": "external",
                    "summary": "Source - osv",
                    "url": "https://www.googleapis.com/download/storage/v1/b/osv-vulnerabilities/o/GIT%2FCVE-2025-70397.json?alt=media"
                },
                {
                    "category": "external",
                    "summary": "Source - first",
                    "url": "https://api.first.org/data/v1/epss?limit=10000&offset=10000"
                },
                {
                    "category": "external",
                    "summary": "Source - nvd",
                    "url": "https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2025-70397"
                },
                {
                    "category": "external",
                    "summary": "Reference - cveprojectv5; nvd; osv",
                    "url": "http://jizhicms.com/"
                },
                {
                    "category": "external",
                    "summary": "Reference - cveprojectv5; nvd; osv",
                    "url": "https://www.23882.me/index.php/2026/02/15/jizhicms-%e5%90%8e%e5%8f%b0%e5%ad%98%e5%9c%a8sql%e6%b3%a8%e5%85%a5/"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
                        "baseScore": 7.2,
                        "baseSeverity": "HIGH"
                    },
                    "products": [
                        "CSAFPID-3463215",
                        "CSAFPID-3463216",
                        "CSAFPID-3463217",
                        "CSAFPID-3463218",
                        "CSAFPID-3463219",
                        "CSAFPID-3463220",
                        "CSAFPID-3463221",
                        "CSAFPID-3463222",
                        "CSAFPID-3463223",
                        "CSAFPID-3463224",
                        "CSAFPID-3463225",
                        "CSAFPID-3463226",
                        "CSAFPID-3463227",
                        "CSAFPID-3463228",
                        "CSAFPID-3463229",
                        "CSAFPID-3463230",
                        "CSAFPID-3463231",
                        "CSAFPID-3463232",
                        "CSAFPID-3463233",
                        "CSAFPID-3463234",
                        "CSAFPID-3463235",
                        "CSAFPID-3463236",
                        "CSAFPID-3463237",
                        "CSAFPID-3463238",
                        "CSAFPID-3463239",
                        "CSAFPID-3463240",
                        "CSAFPID-3463241",
                        "CSAFPID-3463242",
                        "CSAFPID-3463243",
                        "CSAFPID-3463244",
                        "CSAFPID-3463245",
                        "CSAFPID-3463246",
                        "CSAFPID-3463247",
                        "CSAFPID-3627305",
                        "CSAFPID-3627306",
                        "CSAFPID-3627307",
                        "CSAFPID-3627308",
                        "CSAFPID-3627309",
                        "CSAFPID-3796369",
                        "CSAFPID-3796370",
                        "CSAFPID-3796371",
                        "CSAFPID-3796372",
                        "CSAFPID-3796373",
                        "CSAFPID-5262780",
                        "CSAFPID-5630885",
                        "CSAFPID-5658542"
                    ]
                }
            ],
            "title": "CVE-2025-70397"
        }
    ]
}