First published: Tue Sep 19 2023(Updated: )
An issue in the component /common/DownController.java of JFinalCMS v5.0.0 allows attackers to execute a directory traversal.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
JFinalCMS | =5.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2023-41599 is medium with a severity value of 5.3.
The affected software version of CVE-2023-41599 is JFinalCMS v5.0.0.
CVE-2023-41599 allows attackers to execute a directory traversal through the component /common/DownController.java of JFinalCMS v5.0.0.
The Common Weakness Enumeration (CWE) of CVE-2023-41599 is CWE-22.
To fix the directory traversal vulnerability in JFinalCMS v5.0.0, apply the latest patch or upgrade to a version that addresses the issue.