Vulnerabilities > Jflyfox > Jfinal CMS > 2.9.1

DATE CVE VULNERABILITY TITLE RISK
2021-09-15 CVE-2020-19146 Path Traversal vulnerability in Jflyfox Jfinal CMS
Improper Access Control in Jfinal CMS v4.7.1 and earlier allows remote attackers to obtain sensitive information via the 'TemplatePath' parameter in the component 'jfinal_cms/admin/folder/list'.
network
low complexity
jflyfox CWE-22
4.0
2021-09-15 CVE-2020-19147 Path Traversal vulnerability in Jflyfox Jfinal CMS
Improper Access Control in Jfinal CMS v4.7.1 and earlier allows remote attackers to obtain sensitive infromation via the 'getFolder()' function in the component '/modules/filemanager/FileManager.java'.
network
low complexity
jflyfox CWE-22
4.0
2021-09-15 CVE-2020-19148 Cross-site Scripting vulnerability in Jflyfox Jfinal CMS
Cross Site Scripting (XSS) in Jfinal CMS v4.7.1 and earlier allows remote attackers to execute arbitrary code via the 'Nickname' parameter in the component '/jfinal_cms/front/person/profile.html'.
network
jflyfox CWE-79
3.5
2021-09-15 CVE-2020-19150 Path Traversal vulnerability in Jflyfox Jfinal CMS
Improper Access Control in Jfinal CMS v4.7.1 and earlier allows remote attackers to obtain sensitive information or cause a denial of service via the 'FileManager.delete()' function in the component 'modules/filemanager/FileManagerController.java'.
network
low complexity
jflyfox CWE-22
5.5
2021-09-15 CVE-2020-19151 Command Injection vulnerability in Jflyfox Jfinal CMS
Command Injection in Jfinal CMS v4.7.1 and earlier allows remote attackers to execute arbitrary code by uploading a malicious HTML template file via the component 'jfinal_cms/admin/filemanager/list'.
network
low complexity
jflyfox CWE-77
6.5
2021-09-15 CVE-2020-19154 Path Traversal vulnerability in Jflyfox Jfinal CMS
Improper Access Control in Jfinal CMS v4.7.1 and earlier allows remote attackers to obtain sensitive information via the 'FileManager.editFile()' function in the component 'modules/filemanager/FileManagerController.java'.
network
low complexity
jflyfox CWE-22
4.0
2021-09-15 CVE-2020-19155 Exposure of Resource to Wrong Sphere vulnerability in Jflyfox Jfinal CMS
Improper Access Control in Jfinal CMS v4.7.1 and earlier allows remote attackers to obtain sensitive information and/or execute arbitrary code via the 'FileManager.rename()' function in the component 'modules/filemanager/FileManagerController.java'.
network
low complexity
jflyfox CWE-668
8.8