First published: Thu Feb 09 2023(Updated: )
A vulnerability was found in glorylion JFinalOA 1.0.2 and classified as critical. This issue affects some unknown processing of the file src/main/java/com/pointlion/mvc/common/model/SysOrg.java. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-220469 was assigned to this vulnerability.
Credit: cna@vuldb.com cna@vuldb.com
Affected Software | Affected Version | How to fix |
---|---|---|
JFinalOA | =1.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-0758 is classified as a critical vulnerability.
To fix CVE-2023-0758, update to a patched version of JFinalOA or mitigate SQL injection risks by validating and sanitizing inputs.
CVE-2023-0758 affects the file src/main/java/com/pointlion/mvc/common/model/SysOrg.java in JFinalOA version 1.0.2.
Yes, CVE-2023-0758 can be exploited remotely via SQL injection through crafted requests.
CVE-2023-0758 specifically affects JFinalOA version 1.0.2.