MEDIUM5.4
GHSA-9pvq-4cc7-24jg
Cross-site Scripting in Jfinal CMS
Details
Jfinal CMS v5.1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the keyword text field under the publish blog module.
Are you affected?
Enter the version of the package you're using.
Affected packages
Maven/com.jfinal:jfinal
Introduced in:
0No fixed version published yet for com.jfinal:jfinal (maven). Pin to a known-safe version or switch to an alternative.