PT-2021-20123 · Jfinal · Jfinal

Ghost

·

Published

2021-06-24

·

Updated

2021-08-13

·

CVE-2021-33348

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions JFinal framework versions 4.9.10 and below
Description An issue in the JFinal framework allows for XSS vulnerabilities due to insufficient filtering in the set method of the Controller class.
Recommendations For JFinal framework versions 4.9.10 and below, consider updating to a version above 4.9.10 to resolve the issue. As a temporary workaround, restrict the use of the set method in the Controller class to minimize the risk of exploitation.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-33348
GHSA-2C25-XFPQ-8W9R

Affected Products

Jfinal