Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Glassyamadeus

#36228de 53,633
7.5CVSS total
Vulnerabilidades · 1
PT-2019-15098
7.5
2019-10-08
Jfinal · Jfinal · CVE-2019-17352
**Name of the Vulnerable Software and Affected Versions** JFinal cos before 2019-08-13 JFinal version 4.4 **Description** The issue allows bypassing the `isSafeFile()` function, enabling the upload of any file type. For instance, a `.jsp` file can be uploaded, stored, and potentially deleted immediately, but certain exceptions may prevent this deletion. **Recommendations** For JFinal cos before 2019-08-13, consider updating to a version released after 2019-08-13 to address the issue. For JFinal version 4.4, consider updating to a version that incorporates the fix for the `isSafeFile()` function bypass vulnerability.