Show filters
49 Total Results
Displaying 1-10 of 49
Sort by:
Attacker Value
Unknown
CVE-2023-47503
Disclosure Date: November 28, 2023 (last updated December 02, 2023)
An issue in jflyfox jfinalCMS v.5.1.0 allows a remote attacker to execute arbitrary code via a crafted script to the login.jsp component in the template management module.
0
Attacker Value
Unknown
CVE-2023-34645
Disclosure Date: June 16, 2023 (last updated October 08, 2023)
jfinal CMS 5.1.0 has an arbitrary file read vulnerability.
0
Attacker Value
Unknown
CVE-2023-30349
Disclosure Date: April 27, 2023 (last updated February 24, 2025)
JFinal CMS v5.1.0 was discovered to contain a remote code execution (RCE) vulnerability via the ActionEnter function.
0
Attacker Value
Unknown
CVE-2023-24747
Disclosure Date: April 05, 2023 (last updated February 24, 2025)
Jfinal CMS v5.1 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /system/dict/list.
0
Attacker Value
Unknown
CVE-2023-22975
Disclosure Date: February 03, 2023 (last updated February 24, 2025)
A cross-site scripting (XSS) vulnerability in JFinal CMS v5.1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the email parameter under /front/person/profile.html.
0
Attacker Value
Unknown
CVE-2022-37202
Disclosure Date: October 26, 2022 (last updated February 24, 2025)
JFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/advicefeedback/list
0
Attacker Value
Unknown
CVE-2022-37208
Disclosure Date: October 13, 2022 (last updated February 24, 2025)
JFinal CMS 5.1.0 is vulnerable to SQL Injection. These interfaces do not use the same component, nor do they have filters, but each uses its own SQL concatenation method, resulting in SQL injection.
0
Attacker Value
Unknown
CVE-2022-37209
Disclosure Date: September 27, 2022 (last updated February 24, 2025)
JFinal CMS 5.1.0 is affected by: SQL Injection. These interfaces do not use the same component, nor do they have filters, but each uses its own SQL concatenation method, resulting in SQL injection.
0
Attacker Value
Unknown
CVE-2022-37205
Disclosure Date: September 20, 2022 (last updated February 24, 2025)
JFinal CMS 5.1.0 is affected by: SQL Injection. These interfaces do not use the same component, nor do they have filters, but each uses its own SQL concatenation method, resulting in SQL injection.
0
Attacker Value
Unknown
CVE-2022-37204
Disclosure Date: September 20, 2022 (last updated February 24, 2025)
Final CMS 5.1.0 is vulnerable to SQL Injection.
0