In jfinal_cms >= 5.1 0, there is a storage XSS vulnerability in the background system of CMS. Because developers do not filter the parameters submitted by the user input form, any user with background permission can affect the system security by entering malicious code.
References
Link | Resource |
---|---|
https://github.com/jflyfox/jfinal_cms/issues/19 | Exploit Issue Tracking Third Party Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: mitre
Published: 2022-01-25T15:56:49
Updated: 2022-01-25T15:56:48
Reserved: 2022-01-03T00:00:00
Link: CVE-2021-46087
JSON object: View
NVD Information
Status : Analyzed
Published: 2022-01-25T16:15:09.013
Modified: 2022-01-28T20:45:50.887
Link: CVE-2021-46087
JSON object: View
Redhat Information
No data.
CWE