Show filters
40 Total Results
Displaying 11-20 of 40
Sort by:
Attacker Value
Unknown

CVE-2022-37203

Disclosure Date: September 19, 2022 (last updated February 24, 2025)
JFinal CMS 5.1.0 is vulnerable to SQL Injection. These interfaces do not use the same component, nor do they have filters, but each uses its own SQL concatenation method, resulting in SQL injection.
Attacker Value
Unknown

CVE-2022-37201

Disclosure Date: September 15, 2022 (last updated February 24, 2025)
JFinal CMS 5.1.0 is vulnerable to SQL Injection.
Attacker Value
Unknown

CVE-2022-37207

Disclosure Date: September 15, 2022 (last updated February 24, 2025)
JFinal CMS 5.1.0 is affected by: SQL Injection. These interfaces do not use the same component, nor do they have filters, but each uses its own SQL concatenation method, resulting in SQL injection
Attacker Value
Unknown

CVE-2022-38286

Disclosure Date: September 09, 2022 (last updated February 24, 2025)
JFinal CMS 5.1.0 is vulnerable to SQL Injection via /system/role/list.
Attacker Value
Unknown

CVE-2022-38285

Disclosure Date: September 09, 2022 (last updated February 24, 2025)
JFinal CMS 5.1.0 is vulnerable to SQL Injection via /system/menu/list.
Attacker Value
Unknown

CVE-2022-38284

Disclosure Date: September 09, 2022 (last updated February 24, 2025)
JFinal CMS 5.1.0 is vulnerable to SQL Injection via /system/department/list.
Attacker Value
Unknown

CVE-2022-38283

Disclosure Date: September 09, 2022 (last updated February 24, 2025)
JFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/video/list.
Attacker Value
Unknown

CVE-2022-38282

Disclosure Date: September 09, 2022 (last updated February 24, 2025)
JFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/videoalbum/list.
Attacker Value
Unknown

CVE-2022-38281

Disclosure Date: September 09, 2022 (last updated February 24, 2025)
JFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/site/list.
Attacker Value
Unknown

CVE-2022-38280

Disclosure Date: September 09, 2022 (last updated February 24, 2025)
JFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/image/list.