Show filters
49 Total Results
Displaying 1-10 of 49
Sort by:
Attacker Value
Unknown

CVE-2023-47503

Disclosure Date: November 28, 2023 (last updated December 02, 2023)
An issue in jflyfox jfinalCMS v.5.1.0 allows a remote attacker to execute arbitrary code via a crafted script to the login.jsp component in the template management module.
Attacker Value
Unknown

CVE-2023-34645

Disclosure Date: June 16, 2023 (last updated October 08, 2023)
jfinal CMS 5.1.0 has an arbitrary file read vulnerability.
Attacker Value
Unknown

CVE-2023-30349

Disclosure Date: April 27, 2023 (last updated October 08, 2023)
JFinal CMS v5.1.0 was discovered to contain a remote code execution (RCE) vulnerability via the ActionEnter function.
Attacker Value
Unknown

CVE-2023-24747

Disclosure Date: April 05, 2023 (last updated October 08, 2023)
Jfinal CMS v5.1 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /system/dict/list.
Attacker Value
Unknown

CVE-2023-22975

Disclosure Date: February 03, 2023 (last updated March 08, 2024)
A cross-site scripting (XSS) vulnerability in JFinal CMS v5.1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the email parameter under /front/person/profile.html.
Attacker Value
Unknown

CVE-2022-37202

Disclosure Date: October 26, 2022 (last updated December 22, 2024)
JFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/advicefeedback/list
Attacker Value
Unknown

CVE-2022-37208

Disclosure Date: October 13, 2022 (last updated October 08, 2023)
JFinal CMS 5.1.0 is vulnerable to SQL Injection. These interfaces do not use the same component, nor do they have filters, but each uses its own SQL concatenation method, resulting in SQL injection.
Attacker Value
Unknown

CVE-2022-37209

Disclosure Date: September 27, 2022 (last updated October 08, 2023)
JFinal CMS 5.1.0 is affected by: SQL Injection. These interfaces do not use the same component, nor do they have filters, but each uses its own SQL concatenation method, resulting in SQL injection.
Attacker Value
Unknown

CVE-2022-37205

Disclosure Date: September 20, 2022 (last updated October 08, 2023)
JFinal CMS 5.1.0 is affected by: SQL Injection. These interfaces do not use the same component, nor do they have filters, but each uses its own SQL concatenation method, resulting in SQL injection.
Attacker Value
Unknown

CVE-2022-37204

Disclosure Date: September 20, 2022 (last updated October 08, 2023)
Final CMS 5.1.0 is vulnerable to SQL Injection.