First published: Tue Aug 23 2022(Updated: )
JFinal CMS 5.1.0 is vulnerable to SQL Injection via /jfinal_cms/system/user/list.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Jflyfox Jfinal Cms | =5.1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this JFinal CMS vulnerability is CVE-2022-37199.
CVE-2022-37199 has a severity rating of critical (9.8).
The SQL Injection vulnerability in JFinal CMS 5.1.0 occurs via the /jfinal_cms/system/user/list endpoint.
This vulnerability affects JFinal CMS version 5.1.0.
Yes, a fix for CVE-2022-37199 is available. Please refer to the provided reference for more details.