Critical severity9.8NVD Advisory· Published Sep 19, 2022· Updated Jun 17, 2026
CVE-2022-37203
CVE-2022-37203
Description
JFinal CMS 5.1.0 is vulnerable to SQL Injection. These interfaces do not use the same component, nor do they have filters, but each uses its own SQL concatenation method, resulting in SQL injection.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- cpe:2.3:a:jflyfox:jfinal_cms:5.1.0:*:*:*:*:*:*:*
- JFinal/CMSdescription
Patches
Vulnerability mechanics
References
2- github.com/AgainstTheLight/someEXP_of_jfinal_cms/blob/main/jfinal_cms/sql3.mdnvdExploitThird Party Advisory
- github.com/AgainstTheLight/CVE-2022-37203/blob/main/README.mdnvdThird Party Advisory
News mentions
0No linked articles in our index yet.