First published: Tue Dec 05 2023(Updated: )
JFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/slide/save.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
maven/com.jfinal:jfinal | <=5.0.0 | |
JFinalCMS | =5.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-49372 is a Cross-Site Request Forgery (CSRF) vulnerability in JFinalCMS v5.0.0.
The CSRF vulnerability in JFinalCMS v5.0.0 can be exploited by an attacker to perform unauthorized actions on behalf of an authenticated user.
The severity of CVE-2023-49372 is rated as high with a severity score of 8.8.
To fix the CSRF vulnerability, it is recommended to update JFinalCMS to a version that includes a patch for the vulnerability.
You can find more information about CVE-2023-49372 at the following reference: [link](https://github.com/li-yu320/cms/blob/main/There%20is%20a%20CSRF%20present%20at%20the%20new%20location%20of%20the%20rotation%20image.md)