Jfinalcms · Jfinalcms · CVE-2021-42242
**Name of the Vulnerable Software and Affected Versions**
jfinal cms version 5.0.1
**Description**
A command execution issue exists via the com.jflyfox.component.controller.Ueditor component.
**Recommendations**
For jfinal cms version 5.0.1, consider restricting access to the com.jflyfox.component.controller.Ueditor component to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.