First published: Tue Dec 05 2023(Updated: )
JFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/category/delete.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
maven/com.jfinal:jfinal | <=5.0.0 | |
Jfinalcms | =5.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2023-49398 is high with a severity value of 8.8.
The Cross-Site Request Forgery (CSRF) vulnerability in JFinalCMS v5.0.0 allows an attacker to perform unwanted actions on behalf of an authenticated user by tricking them into clicking a malicious link or visiting a compromised website.
The affected software version of CVE-2023-49398 is JFinalCMS v5.0.0.
To fix the CSRF vulnerability in JFinalCMS v5.0.0, apply the latest security patches or updates provided by the JFinalCMS project.
You can find more information about the CSRF vulnerability in JFinalCMS v5.0.0 at the following link: [GitHub - CSRF exists at the deletion point of column management](https://github.com/nightcloudos/new_cms/blob/main/CSRF%20exists%20at%20the%20deletion%20point%20of%20column%20management.md)