First published: Mon Sep 19 2022(Updated: )
JFinal CMS 5.1.0 is vulnerable to SQL Injection. These interfaces do not use the same component, nor do they have filters, but each uses its own SQL concatenation method, resulting in SQL injection.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Jflyfox Jfinal Cms | =5.1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of JFinal CMS 5.1.0 is CVE-2022-37203.
The severity of CVE-2022-37203 is critical with a severity value of 9.8.
JFinal CMS 5.1.0 becomes vulnerable to SQL Injection due to the usage of different components and SQL concatenation methods without proper filters.
The software version affected by CVE-2022-37203 is JFinal CMS 5.1.0.
At the moment, there is no known fix available for CVE-2022-37203. It is recommended to patch or upgrade JFinal CMS to a non-vulnerable version when it becomes available.