First published: Fri Sep 09 2022(Updated: )
JFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/friendlylink/list.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Jflyfox Jfinal Cms | =5.1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2022-38278.
The affected software is JFinal CMS version 5.1.0.
The severity of CVE-2022-38278 is high, with a severity value of 7.2.
CVE-2022-38278 is a SQL Injection vulnerability in JFinal CMS version 5.1.0 via the /admin/friendlylink/list endpoint.
Currently, there is no fix available for CVE-2022-38278. It is recommended to upgrade to a patched version when it becomes available.