First published: Wed Mar 30 2022(Updated: )
An SQL Injection vulnerability exists in glorylion JFinalOA as of 9/7/2021 in the defkey parameter getHaveDoneTaskDataList method of the FlowTaskController.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
JFinalOA | =2021-09-07 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-40645 has a medium severity rating due to its potential for SQL Injection exploitation.
To fix CVE-2021-40645, validate and sanitize user inputs in the defkey parameter of the FlowTaskController.
CVE-2021-40645 affects JFinalOA version 2021-09-07.
CVE-2021-40645 is classified as an SQL Injection vulnerability.
CVE-2021-40645 can be exploited through specially crafted parameters that manipulate SQL queries in the affected method.