CVE-2022-27111
- EPSS 0.19%
- Veröffentlicht 11.04.2022 15:15:09
- Zuletzt bearbeitet 21.11.2024 06:55:10
Jfinal_CMS 5.1.0 allows attackers to use the feedback function to send malicious XSS code to the administrator backend and execute it.
CVE-2021-46087
- EPSS 0.19%
- Veröffentlicht 25.01.2022 16:15:09
- Zuletzt bearbeitet 21.11.2024 06:33:37
In jfinal_cms >= 5.1 0, there is a storage XSS vulnerability in the background system of CMS. Because developers do not filter the parameters submitted by the user input form, any user with background permission can affect the system security by ente...
CVE-2021-37262
- EPSS 0.37%
- Veröffentlicht 16.12.2021 19:15:08
- Zuletzt bearbeitet 21.11.2024 06:14:54
JFinal_cms 5.1.0 is vulnerable to regex injection that may lead to Denial of Service.
CVE-2021-40639
- EPSS 0.29%
- Veröffentlicht 15.09.2021 22:15:10
- Zuletzt bearbeitet 21.11.2024 06:24:29
Improper access control in Jfinal CMS 5.1.0 allows attackers to access sensitive information via /classes/conf/db.properties&config=filemanager.config.js.
CVE-2020-19155
- EPSS 3.09%
- Veröffentlicht 15.09.2021 14:15:08
- Zuletzt bearbeitet 21.11.2024 05:08:59
Improper Access Control in Jfinal CMS v4.7.1 and earlier allows remote attackers to obtain sensitive information and/or execute arbitrary code via the 'FileManager.rename()' function in the component 'modules/filemanager/FileManagerController.java'.
CVE-2020-19154
- EPSS 0.13%
- Veröffentlicht 15.09.2021 14:15:08
- Zuletzt bearbeitet 21.11.2024 05:08:59
Improper Access Control in Jfinal CMS v4.7.1 and earlier allows remote attackers to obtain sensitive information via the 'FileManager.editFile()' function in the component 'modules/filemanager/FileManagerController.java'.
CVE-2020-19151
- EPSS 1.73%
- Veröffentlicht 15.09.2021 14:15:08
- Zuletzt bearbeitet 21.11.2024 05:08:59
Command Injection in Jfinal CMS v4.7.1 and earlier allows remote attackers to execute arbitrary code by uploading a malicious HTML template file via the component 'jfinal_cms/admin/filemanager/list'.
CVE-2020-19150
- EPSS 0.58%
- Veröffentlicht 15.09.2021 14:15:08
- Zuletzt bearbeitet 21.11.2024 05:08:58
Improper Access Control in Jfinal CMS v4.7.1 and earlier allows remote attackers to obtain sensitive information or cause a denial of service via the 'FileManager.delete()' function in the component 'modules/filemanager/FileManagerController.java'.
CVE-2020-19148
- EPSS 0.51%
- Veröffentlicht 15.09.2021 14:15:08
- Zuletzt bearbeitet 21.11.2024 05:08:58
Cross Site Scripting (XSS) in Jfinal CMS v4.7.1 and earlier allows remote attackers to execute arbitrary code via the 'Nickname' parameter in the component '/jfinal_cms/front/person/profile.html'.
CVE-2020-19146
- EPSS 0.19%
- Veröffentlicht 15.09.2021 14:15:07
- Zuletzt bearbeitet 21.11.2024 05:08:58
Improper Access Control in Jfinal CMS v4.7.1 and earlier allows remote attackers to obtain sensitive information via the 'TemplatePath' parameter in the component 'jfinal_cms/admin/folder/list'.