Show filters
49 Total Results
Displaying 41-49 of 49
Sort by:
Attacker Value
Unknown

CVE-2021-37262

Disclosure Date: December 16, 2021 (last updated February 23, 2025)
JFinal_cms 5.1.0 is vulnerable to regex injection that may lead to Denial of Service.
Attacker Value
Unknown

CVE-2021-40639

Disclosure Date: September 15, 2021 (last updated February 23, 2025)
Improper access control in Jfinal CMS 5.1.0 allows attackers to access sensitive information via /classes/conf/db.properties&config=filemanager.config.js.
Attacker Value
Unknown

CVE-2020-19151

Disclosure Date: September 15, 2021 (last updated February 23, 2025)
Command Injection in Jfinal CMS v4.7.1 and earlier allows remote attackers to execute arbitrary code by uploading a malicious HTML template file via the component 'jfinal_cms/admin/filemanager/list'.
Attacker Value
Unknown

CVE-2020-19150

Disclosure Date: September 15, 2021 (last updated February 23, 2025)
Improper Access Control in Jfinal CMS v4.7.1 and earlier allows remote attackers to obtain sensitive information or cause a denial of service via the 'FileManager.delete()' function in the component 'modules/filemanager/FileManagerController.java'.
Attacker Value
Unknown

CVE-2020-19154

Disclosure Date: September 15, 2021 (last updated February 23, 2025)
Improper Access Control in Jfinal CMS v4.7.1 and earlier allows remote attackers to obtain sensitive information via the 'FileManager.editFile()' function in the component 'modules/filemanager/FileManagerController.java'.
Attacker Value
Unknown

CVE-2020-19148

Disclosure Date: September 15, 2021 (last updated February 23, 2025)
Cross Site Scripting (XSS) in Jfinal CMS v4.7.1 and earlier allows remote attackers to execute arbitrary code via the 'Nickname' parameter in the component '/jfinal_cms/front/person/profile.html'.
Attacker Value
Unknown

CVE-2020-19155

Disclosure Date: September 15, 2021 (last updated February 23, 2025)
Improper Access Control in Jfinal CMS v4.7.1 and earlier allows remote attackers to obtain sensitive information and/or execute arbitrary code via the 'FileManager.rename()' function in the component 'modules/filemanager/FileManagerController.java'.
Attacker Value
Unknown

CVE-2020-19146

Disclosure Date: September 15, 2021 (last updated February 23, 2025)
Improper Access Control in Jfinal CMS v4.7.1 and earlier allows remote attackers to obtain sensitive information via the 'TemplatePath' parameter in the component 'jfinal_cms/admin/folder/list'.
Attacker Value
Unknown

CVE-2020-19147

Disclosure Date: September 15, 2021 (last updated February 23, 2025)
Improper Access Control in Jfinal CMS v4.7.1 and earlier allows remote attackers to obtain sensitive infromation via the 'getFolder()' function in the component '/modules/filemanager/FileManager.java'.