Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Arongmho

#20353of 53,635
12.6Total CVSS
Vulnerabilities · 2
Medium
1
High
1
PT-2022-21695
5.4
2022-06-23
Jfinalcms · Jfinalcms · CVE-2022-33113
**Name of the Vulnerable Software and Affected Versions** Jfinal CMS version 5.1.0 **Description** The issue allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the `keyword` text field under the publish blog module. **Recommendations** For Jfinal CMS version 5.1.0, consider restricting access to the publish blog module until a fix is available. As a temporary workaround, avoid using the `keyword` text field in the publish blog module to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
PT-2022-21696
7.2
2022-06-23
Jfinalcms · Jfinalcms · CVE-2022-33114
**Name of the Vulnerable Software and Affected Versions** Jfinal CMS version 5.1.0 **Description** A SQL injection issue was discovered in Jfinal CMS via the `attrVal` parameter at the "/jfinal cms/system/dict/list" API endpoint. This allows for potential exploitation. **Recommendations** For Jfinal CMS version 5.1.0, consider restricting access to the "/jfinal cms/system/dict/list" API endpoint to minimize the risk of exploitation. Avoid using the `attrVal` parameter in this endpoint until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.