PT-2024-20374 · Jfinalcms · Jfinalcms

Published

2024-03-07

·

Updated

2024-08-29

·

CVE-2024-24375

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Jfinalcms version 5.0.0
Description A SQL injection issue allows a remote attacker to obtain sensitive information. The issue is related to the /admin/admin API endpoint, specifically the name parameter.
Recommendations For Jfinalcms version 5.0.0, avoid using the name parameter in the /admin/admin API endpoint until the issue is resolved. Consider restricting access to this endpoint to minimize the risk of exploitation.

Exploit

Fix

SQL injection

Cleartext Storage of Sensitive Information

Weakness Enumeration

Related Identifiers

CVE-2024-24375

Affected Products

Jfinalcms