VYPR
Moderate severityNVD Advisory· Published Dec 14, 2023· Updated Aug 2, 2024

CVE-2023-50100

CVE-2023-50100

Description

JFinalcms 5.0.0 is vulnerable to Cross Site Scripting (XSS) via carousel image editing.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

JFinalCMS 5.0.0 contains a stored cross-site scripting vulnerability in the carousel image editing function.

Vulnerability

JFinalCMS 5.0.0 is vulnerable to stored cross-site scripting (XSS) in the carousel image editing functionality. The application fails to properly sanitize user-supplied input, allowing an attacker to inject arbitrary web script or HTML which is then stored and executed in the context of the user's browser when the image is loaded [1][2].

Exploitation

To exploit this vulnerability, an attacker must have access to the carousel image editing interface. The attacker can inject malicious script payloads into one of the image fields (such as the image URL or description). Because the input is not sanitized before storage, the payload is saved to the server and later rendered unsafely in the admin dashboard, triggering execution for any user who views the affected carousel item [2].

Impact

Successful exploitation enables an attacker to execute arbitrary JavaScript in the context of an authenticated administrator's session. This can lead to session hijacking, data theft, or defacement of the admin panel. The stored nature of the XSS increases the impact, as the payload persists across visits and can affect multiple users [1][2].

Mitigation

As of the advisory date, no official patch has been released for JFinalCMS 5.0.0. Users should manually validate and sanitize all image-related input fields in the carousel editing module. A proper content security policy (CSP) can also help mitigate the risk. The vendor has been made aware through the disclosure on GitHub [2].

AI Insight generated on May 20, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
com.jfinal:jfinalMaven
<= 5.0.0

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.