JFinal CMS 5.1.0 is vulnerable to SQL Injection. These interfaces do not use the same component, nor do they have filters, but each uses its own SQL concatenation method, resulting in SQL injection.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2022-09-19T15:26:22

Updated: 2022-09-19T15:26:22

Reserved: 2022-08-01T00:00:00


Link: CVE-2022-37203

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2022-09-19T16:15:11.307

Modified: 2022-09-21T17:40:03.263


Link: CVE-2022-37203

JSON object: View

cve-icon Redhat Information

No data.

CWE