First published: Mon Jun 26 2023(Updated: )
Server-Side Template Injection (SSTI) vulnerability in jFinal v.4.9.08 allows a remote attacker to execute arbitrary code via the template function.
Credit: cve@mitre.org cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Jfinal Jfinal | =4.9.08 | |
maven/com.jfinal:jfinal | <=4.9.08 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2021-31635 is critical.
CVE-2021-31635 affects jFinal version 4.9.08.
Server-Side Template Injection (SSTI) is a vulnerability that allows an attacker to execute arbitrary code via the template function.
A remote attacker can exploit CVE-2021-31635 by executing arbitrary code through the template function.
Yes, a fix for CVE-2021-31635 is available. Please update to a version of jFinal that is not affected by the vulnerability.