First published: Tue Sep 27 2022(Updated: )
JFinal CMS 5.1.0 is affected by: SQL Injection. These interfaces do not use the same component, nor do they have filters, but each uses its own SQL concatenation method, resulting in SQL injection.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Jfinalcms | =5.1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for JFinal CMS 5.1.0 is CVE-2022-37209.
CVE-2022-37209 has a severity keyword of 'high' and a severity value of 8.8.
The affected software for CVE-2022-37209 is Jflyfox Jfinal Cms version 5.1.0.
JFinal CMS 5.1.0 is affected by a SQL Injection vulnerability where each interface uses its own SQL concatenation method, resulting in SQL injection.
The SQL Injection vulnerability can be exploited by manipulating the SQL concatenation method used by the affected interfaces in JFinal CMS 5.1.0.