VDB
Sign up
MEDIUM5.4

GHSA-9pvq-4cc7-24jg

Cross-site Scripting in Jfinal CMS

Details

Jfinal CMS v5.1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the keyword text field under the publish blog module.

Are you affected?

Enter the version of the package you're using.

Affected packages

Maven/com.jfinal:jfinal
Introduced in: 0

No fixed version published yet for com.jfinal:jfinal (maven). Pin to a known-safe version or switch to an alternative.

References