High severity7.5NVD Advisory· Published Sep 15, 2021· Updated Jul 9, 2026
CVE-2021-40639
CVE-2021-40639
Description
Improper access control in Jfinal CMS 5.1.0 allows attackers to access sensitive information via /classes/conf/db.properties&config=filemanager.config.js.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- cpe:2.3:a:jflyfox:jfinal_cms:5.1.0:*:*:*:*:*:*:*
- Jfinal CMS/Jfinal CMSdescription
Patches
Vulnerability mechanics
References
1- github.com/jflyfox/jfinal_cms/issues/27nvdExploitIssue TrackingThird Party Advisory
News mentions
0No linked articles in our index yet.