First published: Tue Jan 23 2024(Updated: )
Cross Site Scripting (XSS) vulnerability in /admin/login password parameter in JFinalcms 5.0.0 allows attackers to run arbitrary code via crafted URL.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
maven/com.jfinal:jfinal | <=5.0.0 | |
JFinalCMS | =5.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-22497 is classified as a high severity vulnerability due to its potential for arbitrary code execution via XSS.
To fix CVE-2024-22497, upgrade JFinalcms to a version higher than 5.0.0 to eliminate the vulnerability.
CVE-2024-22497 affects users of JFinalcms version 5.0.0 and earlier, especially those utilizing the /admin/login feature.
CVE-2024-22497 is a Cross Site Scripting (XSS) vulnerability that can be exploited through crafted URLs.
CVE-2024-22497 allows attackers to execute arbitrary code, potentially compromising the security and integrity of affected systems.