PT-2021-20123 · Jfinal · Jfinal
Ghost
·
Published
2021-06-24
·
Updated
2021-08-13
·
CVE-2021-33348
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
JFinal framework versions 4.9.10 and below
Description
An issue in the JFinal framework allows for XSS vulnerabilities due to insufficient filtering in the
set method of the Controller class.Recommendations
For JFinal framework versions 4.9.10 and below, consider updating to a version above 4.9.10 to resolve the issue. As a temporary workaround, restrict the use of the
set method in the Controller class to minimize the risk of exploitation.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Jfinal