First published: Tue May 03 2022(Updated: )
Jfinal_cms 5.1.0 is vulnerable to SQL Injection via com.jflyfox.system.log.LogController.java.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Jflyfox Jfinal Cms | =5.1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-28505 is a vulnerability in Jfinal_cms 5.1.0 that allows SQL Injection via the com.jflyfox.system.log.LogController.java component.
CVE-2022-28505 has a severity rating of 7.2 (high).
CVE-2022-28505 affects Jfinal_cms 5.1.0 by enabling SQL Injection through the com.jflyfox.system.log.LogController.java file.
To fix CVE-2022-28505, you should update Jfinal_cms to a version that is not vulnerable to this SQL Injection vulnerability.
You can find more information about CVE-2022-28505 at the following reference link: [https://github.com/jflyfox/jfinal_cms/issues/33](https://github.com/jflyfox/jfinal_cms/issues/33)