VYPR

Jfinal

by Jfinal

Source repositories

CVEs (30)

  • CVE-2024-57768CriJan 16, 2025
    risk 0.64cvss 9.8epss 0.01

    JFinalOA before v2025.01.01 was discovered to contain a SQL injection vulnerability via the component validRoleKey?sysRole.key.

  • CVE-2024-53477CriDec 2, 2024
    risk 0.64cvss 9.8epss 0.01

    JFinal CMS 5.1.0 is vulnerable to Command Execution via unauthorized execution of deserialization in the file ApiForm.java

  • CVE-2021-31635CriJun 26, 2023
    risk 0.64cvss 9.8epss 0.01

    Server-Side Template Injection (SSTI) vulnerability in jFinal v.4.9.08 allows a remote attacker to execute arbitrary code via the template function.

  • CVE-2022-37203CriSep 19, 2022
    risk 0.64cvss 9.8epss 0.01

    JFinal CMS 5.1.0 is vulnerable to SQL Injection. These interfaces do not use the same component, nor do they have filters, but each uses its own SQL concatenation method, resulting in SQL injection.

  • CVE-2022-30500CriMay 26, 2022
    risk 0.64cvss 9.8epss 0.01

    Jfinal cms 5.1.0 is vulnerable to SQL Injection.

  • CVE-2021-31649CriJun 24, 2021
    risk 0.64cvss 9.8epss 0.02

    In applications using jfinal 4.9.08 and below, there is a deserialization vulnerability when using redis,may be vulnerable to remote code execute

  • CVE-2020-19151HigSep 15, 2021
    risk 0.58cvss 8.8epss 0.05

    Command Injection in Jfinal CMS v4.7.1 and earlier allows remote attackers to execute arbitrary code by uploading a malicious HTML template file via the component 'jfinal_cms/admin/filemanager/list'.

  • CVE-2024-57775HigJan 16, 2025
    risk 0.57cvss 8.8epss 0.01

    JFinalOA before v2025.01.01 was discovered to contain a SQL injection vulnerability via the component getWorkFlowHis?insid.

  • CVE-2024-57770HigJan 16, 2025
    risk 0.57cvss 8.8epss 0.01

    JFinalOA before v2025.01.01 was discovered to contain a SQL injection vulnerability via the component apply/save#oaContractApply.id.

  • CVE-2024-57769HigJan 16, 2025
    risk 0.57cvss 8.8epss 0.01

    JFinalOA before v2025.01.01 was discovered to contain a SQL injection vulnerability via the component borrowmoney/listData?applyUser.

  • CVE-2022-37202HigOct 26, 2022
    risk 0.57cvss 8.8epss 0.01

    JFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/advicefeedback/list

  • CVE-2022-37208HigOct 13, 2022
    risk 0.57cvss 8.8epss 0.01

    JFinal CMS 5.1.0 is vulnerable to SQL Injection. These interfaces do not use the same component, nor do they have filters, but each uses its own SQL concatenation method, resulting in SQL injection.

  • CVE-2022-37209HigSep 27, 2022
    risk 0.57cvss 8.8epss 0.01

    JFinal CMS 5.1.0 is affected by: SQL Injection. These interfaces do not use the same component, nor do they have filters, but each uses its own SQL concatenation method, resulting in SQL injection.

  • CVE-2022-37205HigSep 20, 2022
    risk 0.57cvss 8.8epss 0.01

    JFinal CMS 5.1.0 is affected by: SQL Injection. These interfaces do not use the same component, nor do they have filters, but each uses its own SQL concatenation method, resulting in SQL injection.

  • CVE-2022-37201HigSep 15, 2022
    risk 0.57cvss 8.8epss 0.01

    JFinal CMS 5.1.0 is vulnerable to SQL Injection.

  • CVE-2022-37207HigSep 15, 2022
    risk 0.57cvss 8.8epss 0.01

    JFinal CMS 5.1.0 is affected by: SQL Injection. These interfaces do not use the same component, nor do they have filters, but each uses its own SQL concatenation method, resulting in SQL injection

  • CVE-2020-19150HigSep 15, 2021
    risk 0.53cvss 8.1epss 0.03

    Improper Access Control in Jfinal CMS v4.7.1 and earlier allows remote attackers to obtain sensitive information or cause a denial of service via the 'FileManager.delete()' function in the component 'modules/filemanager/FileManagerController.java'.

  • CVE-2019-17352HigOct 8, 2019
    risk 0.49cvss 7.5epss 0.02

    In JFinal cos before 2019-08-13, as used in JFinal 4.4, there is a vulnerability that can bypass the isSafeFile() function: one can upload any type of file. For example, a .jsp file may be stored and almost immediately deleted, but this deletion step does not occur for certain…

  • CVE-2020-19154MedSep 15, 2021
    risk 0.43cvss 6.5epss 0.04

    Improper Access Control in Jfinal CMS v4.7.1 and earlier allows remote attackers to obtain sensitive information via the 'FileManager.editFile()' function in the component 'modules/filemanager/FileManagerController.java'.

  • CVE-2020-19147MedSep 15, 2021
    risk 0.42cvss 6.5epss 0.02

    Improper Access Control in Jfinal CMS v4.7.1 and earlier allows remote attackers to obtain sensitive infromation via the 'getFolder()' function in the component '/modules/filemanager/FileManager.java'.

Page 1 of 2