First published: Tue Dec 05 2023(Updated: )
JFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/div/update.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
maven/com.jfinal:jfinal | <=5.0.0 | |
JFinalCMS | =5.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-49381 is a Cross-Site Request Forgery (CSRF) vulnerability in JFinalCMS v5.0.0.
The CSRF vulnerability in JFinalCMS v5.0.0 allows an attacker to trick a authenticated user into performing unintended actions on the vulnerable website.
CVE-2023-49381 has a severity rating of 8.8 (high).
Exploiting the CSRF vulnerability in JFinalCMS v5.0.0 requires the attacker to craft a malicious website or URL and trick the victim into visiting it while being logged into the vulnerable JFinalCMS instance.
To fix the CSRF vulnerability in JFinalCMS v5.0.0, it is recommended to apply the official patch or update to a newer version that addresses the issue.