First published: Thu Oct 13 2022(Updated: )
JFinal CMS 5.1.0 is vulnerable to SQL Injection. These interfaces do not use the same component, nor do they have filters, but each uses its own SQL concatenation method, resulting in SQL injection.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Jflyfox Jfinal Cms | =5.1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-37208 is a SQL Injection vulnerability in JFinal CMS 5.1.0.
CVE-2022-37208 has a severity score of 8.8, which is considered high.
JFinal CMS 5.1.0 is a content management system vulnerable to the SQL Injection vulnerability.
CVE-2022-37208 allows an attacker to inject malicious SQL queries into JFinal CMS 5.1.0, potentially leading to unauthorized access or data manipulation.
At the moment, there is no official fix available for CVE-2022-37208. It is recommended to update to a patched version when one becomes available or implement security measures to mitigate the risk.