First published: Wed Sep 15 2021(Updated: )
Improper Access Control in Jfinal CMS v4.7.1 and earlier allows remote attackers to obtain sensitive information via the 'TemplatePath' parameter in the component 'jfinal_cms/admin/folder/list'.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Jflyfox Jfinal Cms | <=4.7.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-19146 is a vulnerability that is found in Jfinal CMS v4.7.1 and earlier versions, allowing remote attackers to obtain sensitive information.
CVE-2020-19146 works by exploiting an improper access control vulnerability in the 'TemplatePath' parameter of the 'jfinal_cms/admin/folder/list' component in Jfinal CMS.
CVE-2020-19146 has a severity rating of 6.5 (medium).
Yes, Jfinal CMS v4.7.1 and earlier versions are affected by CVE-2020-19146.
To fix CVE-2020-19146, it is recommended to update to a version of Jfinal CMS that is not affected by this vulnerability.