VYPR
Vendor

Jfinaloa Project

Products
1
CVEs
11
Across products
11
Status
Private

Products

1

Recent CVEs

11
  • CVE-2024-57768CriJan 16, 2025
    risk 0.64cvss 9.8epss 0.01

    JFinalOA before v2025.01.01 was discovered to contain a SQL injection vulnerability via the component validRoleKey?sysRole.key.

  • CVE-2024-57775HigJan 16, 2025
    risk 0.57cvss 8.8epss 0.01

    JFinalOA before v2025.01.01 was discovered to contain a SQL injection vulnerability via the component getWorkFlowHis?insid.

  • CVE-2024-57770HigJan 16, 2025
    risk 0.57cvss 8.8epss 0.01

    JFinalOA before v2025.01.01 was discovered to contain a SQL injection vulnerability via the component apply/save#oaContractApply.id.

  • CVE-2024-57769HigJan 16, 2025
    risk 0.57cvss 8.8epss 0.01

    JFinalOA before v2025.01.01 was discovered to contain a SQL injection vulnerability via the component borrowmoney/listData?applyUser.

  • CVE-2021-40645MedMar 30, 2022
    risk 0.42cvss 6.5epss 0.01

    An SQL Injection vulnerability exists in glorylion JFinalOA as of 9/7/2021 in the defkey parameter getHaveDoneTaskDataList method of the FlowTaskController.

  • CVE-2023-0758MedFeb 9, 2023
    risk 0.41cvss 6.3epss 0.01

    A vulnerability was found in glorylion JFinalOA 1.0.2 and classified as critical. This issue affects some unknown processing of the file src/main/java/com/pointlion/mvc/common/model/SysOrg.java. The manipulation of the argument id leads to sql injection. The attack may be…

  • CVE-2024-57774MedJan 16, 2025
    risk 0.31cvss 4.8epss 0.00

    A cross-site scripting (XSS) vulnerability in the getBusinessUploadListPage?busid interface of JFinalOA before v2025.01.01 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.

  • CVE-2024-57773MedJan 16, 2025
    risk 0.31cvss 4.8epss 0.00

    A cross-site scripting (XSS) vulnerability in the openSelectManyUserPage?orgid interface of JFinalOA before v2025.01.01 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.

  • CVE-2024-57772MedJan 16, 2025
    risk 0.31cvss 4.8epss 0.00

    A cross-site scripting (XSS) vulnerability in the /bumph/getDraftListPage?type interface of JFinalOA before v2025.01.01 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.

  • CVE-2024-57771MedJan 16, 2025
    risk 0.31cvss 4.8epss 0.00

    A cross-site scripting (XSS) vulnerability in the common/getEditPage?view interface of JFinalOA before v2025.01.01 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.

  • CVE-2024-57776MedJan 16, 2025
    risk 0.30cvss 4.6epss 0.00

    A cross-site scripting (XSS) vulnerability in the /apply/getEditPage?view interface of JFinalOA before v2025.01.01 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.