First published: Thu Jun 24 2021(Updated: )
An issue was discovered in JFinal framework v4.9.10 and below. The "set" method of the "Controller" class of jfinal framework is not strictly filtered, which will lead to XSS vulnerabilities in some cases.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Jfinal Jfinal | <=4.9.10 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-33348 has a high severity rating due to the potential for XSS attacks.
To fix CVE-2021-33348, update the JFinal framework to version 4.9.11 or later.
CVE-2021-33348 exposes Cross-Site Scripting (XSS) vulnerabilities due to improper input filtering.
CVE-2021-33348 affects JFinal framework versions 4.9.10 and earlier.
Developers and applications using JFinal framework versions 4.9.10 or lower are impacted by CVE-2021-33348.