High severity8.8NVD Advisory· Published Oct 13, 2022· Updated Jun 17, 2026
CVE-2022-37208
CVE-2022-37208
Description
JFinal CMS 5.1.0 is vulnerable to SQL Injection. These interfaces do not use the same component, nor do they have filters, but each uses its own SQL concatenation method, resulting in SQL injection.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- cpe:2.3:a:jflyfox:jfinal_cms:5.1.0:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
1- github.com/AgainstTheLight/someEXP_of_jfinal_cms/blob/main/jfinal_cms/sql5.mdnvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.