Vulnerabilities
54 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2024-57768 | JFinalOA before v2025.01.01 was discovered to contain a SQL injection vulnerability via the component validRoleKey?sysRole.key. JFinalOA before v2025.01.01 was discovered to contain a SQL injection vulnerability via the component validRoleKey?sysRole.key. NVD description · AI analysis pending | 9.8 group max | <1% | PoC |
| — | |
| CVE-2024-40322 | An issue was discovered in JFinalCMS v.5.0.0. An issue was discovered in JFinalCMS v.5.0.0. There is a SQL injection vulnerablity via /admin/div_data/data NVD description · AI analysis pending | 8.8 | <1% | PoC |
| — | |
| CVE-2023-51254 | Cross Site Scripting vulnerability in Jfinalcms v.5.0.0 allows a remote attacker to execute arbitrary code via a crafted script to the friendship link component Cross Site Scripting vulnerability in Jfinalcms v.5.0.0 allows a remote attacker to execute arbitrary code via a crafted script to the friendship link component. NVD description · AI analysis pending | 6.1 | <1% | PoC |
| — | |
| CVE-2024-24375 | SQL injection vulnerability in Jfinalcms v.5.0.0 allows a remote attacker to obtain sensitive information via /admin/admin name parameter. SQL injection vulnerability in Jfinalcms v.5.0.0 allows a remote attacker to obtain sensitive information via /admin/admin name parameter. NVD description · AI analysis pending | 7.5 | <1% | PoC |
| — | |
| CVE-2024-24029 | JFinalCMS 5.0.0 is vulnerable to SQL injection via /admin/content/data. JFinalCMS 5.0.0 is vulnerable to SQL injection via /admin/content/data. NVD description · AI analysis pending | 9.8 | <1% | PoC |
| — | |
| CVE-2024-22497 +1 in the same advisory: …22496 | Cross Site Scripting (XSS) vulnerability in /admin/login password parameter in JFinalcms 5.0.0 allows attackers to run arbitrary code via crafted URL. Cross Site Scripting (XSS) vulnerability in /admin/login password parameter in JFinalcms 5.0.0 allows attackers to run arbitrary code via crafted URL. NVD description · AI analysis pending | 6.1 | <1% | PoC |
| — | |
| CVE-2024-22493 | A stored XSS vulnerability exists in JFinalcms 5.0.0 via the /gusetbook/save content parameter, which allows remote attackers to inject arbitrary web script or A stored XSS vulnerability exists in JFinalcms 5.0.0 via the /gusetbook/save content parameter, which allows remote attackers to inject arbitrary web script or HTML. NVD description · AI analysis pending | 5.4 | <1% | PoC |
| — | |
| CVE-2023-50136 | Cross Site Scripting (XSS) vulnerability in JFinalcms 5.0.0 allows attackers to run arbitrary code via the name field when creating a new custom table. Cross Site Scripting (XSS) vulnerability in JFinalcms 5.0.0 allows attackers to run arbitrary code via the name field when creating a new custom table. NVD description · AI analysis pending | 5.4 | <1% | PoC |
| — | |
| CVE-2023-50137 | JFinalcms 5.0.0 is vulnerable to Cross Site Scripting (XSS) in the site management office. JFinalcms 5.0.0 is vulnerable to Cross Site Scripting (XSS) in the site management office. NVD description · AI analysis pending | 5.4 | <1% | PoC |
| — | |
| CVE-2023-50449 | JFinalCMS 5.0.0 could allow a remote attacker to read files via ../ Directory Traversal in the /common/down/file fileKey parameter. JFinalCMS 5.0.0 could allow a remote attacker to read files via ../ Directory Traversal in the /common/down/file fileKey parameter. NVD description · AI analysis pending | 7.5 | 1% | PoC |
| — | |
| CVE-2023-49486 | JFinalCMS v5.0.0 was discovered to contain a cross-site scripting (XSS) vulnerability in the model management department. JFinalCMS v5.0.0 was discovered to contain a cross-site scripting (XSS) vulnerability in the model management department. NVD description · AI analysis pending | 5.4 | <1% |
| — | ||
| CVE-2023-49448 | JFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via admin/nav/delete. JFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via admin/nav/delete. NVD description · AI analysis pending | 8.8 | <1% | PoC |
| — | |
| CVE-2023-41599 | An issue in the component /common/DownController.java of JFinalCMS v5.0.0 allows attackers to execute a directory traversal. An issue in the component /common/DownController.java of JFinalCMS v5.0.0 allows attackers to execute a directory traversal. NVD description · AI analysis pending | 5.3 | 11% | PoC |
| — | |
| CVE-2021-31635 | Server-Side Template Injection (SSTI) vulnerability in jFinal v.4.9.08 allows a remote attacker to execute arbitrary code via the template function. Server-Side Template Injection (SSTI) vulnerability in jFinal v.4.9.08 allows a remote attacker to execute arbitrary code via the template function. NVD description · AI analysis pending | 9.8 | 1% |
| — | ||
| CVE-2023-0758 | A vulnerability was found in glorylion JFinalOA 1.0.2 and classified as critical. A vulnerability was found in glorylion JFinalOA 1.0.2 and classified as critical. This issue affects some unknown processing of the file src/main/java/com/pointlion/mvc/common/model/SysOrg.java. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-220469 was assigned to this vulnerability. NVD description · AI analysis pending | 9.8 | <1% |
| — | ||
| CVE-2022-27341 | JFinalCMS v2.0 was discovered to contain a SQL injection vulnerability via the Article Management function. JFinalCMS v2.0 was discovered to contain a SQL injection vulnerability via the Article Management function. NVD description · AI analysis pending | 9.8 | 1% | PoC |
| — |