Vulnerabilities > CVE-2021-40639 - Incorrect Authorization vulnerability in Jflyfox Jfinal CMS 5.1.0
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
HIGH Integrity impact
NONE Availability impact
NONE Summary
Improper access control in Jfinal CMS 5.1.0 allows attackers to access sensitive information via /classes/conf/db.properties&config=filemanager.config.js.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |