← Back

Jfinal Cms

jfinal_cms

Vendor: Jflyfox • 51 CVEs

CVEs (51)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Jflyfox
1Jfinal Cms
Nov 21, 2024
Apr 11, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Jfinal_CMS 5.1.0 allows attackers to use the feedback function to send malicious XSS code to the administrator backend and execute it.
1Jflyfox
1Jfinal Cms
Nov 21, 2024
Jan 25, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
In jfinal_cms >= 5.1 0, there is a storage XSS vulnerability in the background system of CMS. Because developers do not filter the parameters submitted by the user input form, any user with background permission can affe...Show more
In jfinal_cms >= 5.1 0, there is a storage XSS vulnerability in the background system of CMS. Because developers do not filter the parameters submitted by the user input form, any user with background permission can affect the system security by entering malicious code.Show less
1Jflyfox
1Jfinal Cms
Nov 21, 2024
Dec 16, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
JFinal_cms 5.1.0 is vulnerable to regex injection that may lead to Denial of Service.
1Jflyfox
1Jfinal Cms
Nov 21, 2024
Sep 15, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Improper access control in Jfinal CMS 5.1.0 allows attackers to access sensitive information via /classes/conf/db.properties&config=filemanager.config.js.
1Jflyfox
1Jfinal Cms
Nov 21, 2024
Sep 15, 2021
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Improper Access Control in Jfinal CMS v4.7.1 and earlier allows remote attackers to obtain sensitive information and/or execute arbitrary code via the 'FileManager.rename()' function in the component 'modules/filemanager...Show more
Improper Access Control in Jfinal CMS v4.7.1 and earlier allows remote attackers to obtain sensitive information and/or execute arbitrary code via the 'FileManager.rename()' function in the component 'modules/filemanager/FileManagerController.java'.Show less
1Jflyfox
1Jfinal Cms
Nov 21, 2024
Sep 15, 2021
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Improper Access Control in Jfinal CMS v4.7.1 and earlier allows remote attackers to obtain sensitive information via the 'FileManager.editFile()' function in the component 'modules/filemanager/FileManagerController.java'...Show more
Improper Access Control in Jfinal CMS v4.7.1 and earlier allows remote attackers to obtain sensitive information via the 'FileManager.editFile()' function in the component 'modules/filemanager/FileManagerController.java'.Show less
1Jflyfox
1Jfinal Cms
Nov 21, 2024
Sep 15, 2021
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Command Injection in Jfinal CMS v4.7.1 and earlier allows remote attackers to execute arbitrary code by uploading a malicious HTML template file via the component 'jfinal_cms/admin/filemanager/list'.
1Jflyfox
1Jfinal Cms
Nov 21, 2024
Sep 15, 2021
N/A· v4
8.1 HIGH· v3
5.5 MEDIUM· v2
Improper Access Control in Jfinal CMS v4.7.1 and earlier allows remote attackers to obtain sensitive information or cause a denial of service via the 'FileManager.delete()' function in the component 'modules/filemanager/...Show more
Improper Access Control in Jfinal CMS v4.7.1 and earlier allows remote attackers to obtain sensitive information or cause a denial of service via the 'FileManager.delete()' function in the component 'modules/filemanager/FileManagerController.java'.Show less
1Jflyfox
1Jfinal Cms
Nov 21, 2024
Sep 15, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Cross Site Scripting (XSS) in Jfinal CMS v4.7.1 and earlier allows remote attackers to execute arbitrary code via the 'Nickname' parameter in the component '/jfinal_cms/front/person/profile.html'.
1Jflyfox
1Jfinal Cms
Nov 21, 2024
Sep 15, 2021
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Improper Access Control in Jfinal CMS v4.7.1 and earlier allows remote attackers to obtain sensitive infromation via the 'getFolder()' function in the component '/modules/filemanager/FileManager.java'.
1Jflyfox
1Jfinal Cms
Nov 21, 2024
Sep 15, 2021
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Improper Access Control in Jfinal CMS v4.7.1 and earlier allows remote attackers to obtain sensitive information via the 'TemplatePath' parameter in the component 'jfinal_cms/admin/folder/list'.