First published: Wed Sep 15 2021(Updated: )
Improper Access Control in Jfinal CMS v4.7.1 and earlier allows remote attackers to obtain sensitive information via the 'FileManager.editFile()' function in the component 'modules/filemanager/FileManagerController.java'.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Jflyfox Jfinal Cms | <=4.7.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-19154 is a vulnerability in Jfinal CMS v4.7.1 and earlier that allows remote attackers to obtain sensitive information.
The vulnerability occurs due to improper access control in the 'FileManager.editFile()' function in the component 'modules/filemanager/FileManagerController.java' of Jfinal CMS.
The severity of CVE-2020-19154 is medium with a CVSS score of 6.5.
Jfinal CMS version 4.7.1 and earlier are affected by CVE-2020-19154.
To fix the vulnerability, it is recommended to update Jfinal CMS to a version beyond 4.7.1.