First published: Thu Sep 15 2022(Updated: )
JFinal CMS 5.1.0 is affected by: SQL Injection. These interfaces do not use the same component, nor do they have filters, but each uses its own SQL concatenation method, resulting in SQL injection
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Jflyfox Jfinal Cms | =5.1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2022-37207 is high.
The affected software version of CVE-2022-37207 is JFinal CMS 5.1.0.
The CWE category of CVE-2022-37207 is CWE-89 (Improper Neutralization of Special Elements used in an SQL Command).
CVE-2022-37207 impacts JFinal CMS by allowing SQL injection attacks due to improper handling of user input.
To fix CVE-2022-37207, it is recommended to update to a patched version of JFinal CMS that addresses the SQL injection vulnerability.