
jflyfox/jfinal_cms
CVE History
| CVE | Published | CVSS v3 | CVSS v2 |
|---|---|---|---|
| 6.3 MEDIUM | 6.5 MEDIUM | ||
A vulnerability was identified in jflyfox jfinal_cms up to 5.1.0. This impacts the function list of the file AdvicefeedbackController.java. Such manipulation of the argument orderBy leads to sql injection. The attack can be launched remotely. The project was informed of the problem early through an issue report but has not responded yet. | |||
| 9.8 CRITICAL | — | ||
JFinal CMS 5.1.0 is vulnerable to Command Execution via unauthorized execution of deserialization in the file ApiForm.java | |||
| 9.8 CRITICAL | — | ||
An issue in jflyfox jfinalCMS v.5.1.0 allows a remote attacker to execute arbitrary code via a crafted script to the login.jsp component in the template management module. | |||
| 7.5 HIGH | — | ||
jfinal CMS 5.1.0 has an arbitrary file read vulnerability. | |||
| — | — | ||
Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: CVE-2023-26813. Reason: This record is a reservation duplicate of CVE-2023-26813. Notes: All CVE users should reference CVE-2023-26813 instead of this record. All references and descriptions in this record have been removed to prevent accidental usage. | |||
| 9.8 CRITICAL | — | ||
JFinal CMS v5.1.0 was discovered to contain a remote code execution (RCE) vulnerability via the ActionEnter function. | |||
| 6.1 MEDIUM | — | ||
A cross-site scripting (XSS) vulnerability in JFinal CMS v5.1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the email parameter under /front/person/profile.html. | |||
| 7.2 HIGH | — | ||
JFinal CMS 5.1.0 is vulnerable to SQL Injection via /system/role/list. | |||
| 7.2 HIGH | — | ||
JFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/folderrollpicture/list. | |||
| 7.2 HIGH | — | ||
JFinal CMS 5.1.0 is vulnerable to SQL Injection via /system/menu/list. | |||
| 7.2 HIGH | — | ||
JFinal CMS 5.1.0 is vulnerable to SQL Injection via /system/department/list. | |||
| 7.2 HIGH | — | ||
JFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/video/list. | |||
| 7.2 HIGH | — | ||
JFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/videoalbum/list. | |||
| 7.2 HIGH | — | ||
JFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/site/list. | |||
| 7.2 HIGH | — | ||
JFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/image/list. | |||
| 7.2 HIGH | — | ||
JFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/imagealbum/list. | |||
| 7.2 HIGH | — | ||
JFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/friendlylink/list. | |||
| 7.2 HIGH | — | ||
JFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/foldernotice/list. | |||
| 7.2 HIGH | — | ||
JFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/contact/list. | |||
| 7.2 HIGH | — | ||
JFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/comment/list. | |||
| 7.2 HIGH | — | ||
JFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/article/list_approve. | |||
| 7.2 HIGH | — | ||
JFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/article/list. | |||
| 5.4 MEDIUM | — | ||
Jfinal CMS v5.1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the post title text field under the publish blog module. | |||
| 9.8 CRITICAL | — | ||
JFinal CMS 5.1.0 is vulnerable to SQL Injection via /jfinal_cms/system/role/list. | |||
| 9.8 CRITICAL | — | ||
JFinal CMS 5.1.0 is vulnerable to SQL Injection via /jfinal_cms/system/user/list. | |||
| 8.8 HIGH | — | ||
JFinal CMS v5.1.0 was discovered to contain a SQL injection vulnerability via /system/user. | |||
| 7.2 HIGH | 6.5 MEDIUM | ||
Jfinal CMS v5.1.0 was discovered to contain a SQL injection vulnerability via the attrVal parameter at /jfinal_cms/system/dict/list. | |||
| 5.4 MEDIUM | 3.5 LOW | ||
Jfinal CMS v5.1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the keyword text field under the publish blog module. | |||
| 5.4 MEDIUM | 3.5 LOW | ||
A cross-site scripting (XSS) vulnerability in Jfinal CMS v5.1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted X-Forwarded-For request. | |||
| 9.8 CRITICAL | 7.5 HIGH | ||
Jfinal cms 5.1.0 is vulnerable to SQL Injection. | |||
| 9.8 CRITICAL | 7.5 HIGH | ||
A command execution vulnerability exists in jfinal_cms 5.0.1 via com.jflyfox.component.controller.Ueditor. | |||
| 7.2 HIGH | 6.5 MEDIUM | ||
Jfinal_cms 5.1.0 is vulnerable to SQL Injection via com.jflyfox.system.log.LogController.java. | |||
| 5.4 MEDIUM | 3.5 LOW | ||
Jfinal_CMS 5.1.0 allows attackers to use the feedback function to send malicious XSS code to the administrator backend and execute it. | |||
| 5.4 MEDIUM | 3.5 LOW | ||
In jfinal_cms >= 5.1 0, there is a storage XSS vulnerability in the background system of CMS. Because developers do not filter the parameters submitted by the user input form, any user with background permission can affect the system security by entering malicious code. | |||
| 7.5 HIGH | 5 MEDIUM | ||
JFinal_cms 5.1.0 is vulnerable to regex injection that may lead to Denial of Service. | |||
| 7.5 HIGH | 5 MEDIUM | ||
Improper access control in Jfinal CMS 5.1.0 allows attackers to access sensitive information via /classes/conf/db.properties&config=filemanager.config.js. | |||