Description
JFinal CMS 5.1.0 is vulnerable to SQL Injection. These interfaces do not use the same component, nor do they have filters, but each uses its own SQL concatenation method, resulting in SQL injection.
References
https://github.com/AgainstTheLight/CVE-2022-37203/blob/main/README.md
Third Party Advisory
https://github.com/AgainstTheLight/someEXP_of_jfinal_cms/blob/main/jfinal_cms/sql3.md
ExploitThird Party Advisory
https://github.com/AgainstTheLight/CVE-2022-37203/blob/main/README.md
Third Party Advisory
https://github.com/AgainstTheLight/someEXP_of_jfinal_cms/blob/main/jfinal_cms/sql3.md
ExploitThird Party Advisory
CVSS impact metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
9.8 · Critical
Information
Source identifier
Vulnerability status
Modified
Published
2022-09-19T14:15:11.307Z
3 years agoLast modified
2024-11-21T06:14:36.513Z
1 year ago