PT-2024-35755 · Jfinalcms · Jfinalcms

Kaoniniang2

·

Published

2024-12-02

·

Updated

2024-12-11

·

CVE-2024-53477

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions JFinal CMS version 5.1.0
Description The issue concerns the unauthorized execution of deserialization in the ApiForm.java file, leading to command execution.
Recommendations For JFinal CMS version 5.1.0, consider disabling the deserialization functionality in the ApiForm.java file as a temporary workaround until a patch is available. Restrict access to the ApiForm.java file to minimize the risk of exploitation. Avoid using the deserialization feature in the affected version until the issue is resolved.

Fix

Deserialization of Untrusted Data

Weakness Enumeration

Related Identifiers

CVE-2024-53477

Affected Products

Jfinalcms