JFinal CMS 5.1.0 is vulnerable to SQL Injection. These interfaces do not use the same component, nor do they have filters, but each uses its own SQL concatenation method, resulting in SQL injection.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2022-10-13T00:00:00

Updated: 2022-10-13T00:00:00

Reserved: 2022-08-01T00:00:00


Link: CVE-2022-37208

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2022-10-13T12:15:11.167

Modified: 2022-10-13T13:02:46.527


Link: CVE-2022-37208

JSON object: View

cve-icon Redhat Information

No data.

CWE