Vulnerabilities > Jflyfox > Medium

DATE CVE VULNERABILITY TITLE RISK
2023-02-03 CVE-2023-22975 Cross-site Scripting vulnerability in Jflyfox Jfinal CMS 5.1.0
A cross-site scripting (XSS) vulnerability in JFinal CMS v5.1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the email parameter under /front/person/profile.html.
network
low complexity
jflyfox CWE-79
6.1
2022-06-23 CVE-2022-33114 SQL Injection vulnerability in Jflyfox Jfinal CMS 5.1.0
Jfinal CMS v5.1.0 was discovered to contain a SQL injection vulnerability via the attrVal parameter at /jfinal_cms/system/dict/list.
network
low complexity
jflyfox CWE-89
6.5
2022-05-03 CVE-2022-28505 SQL Injection vulnerability in Jflyfox Jfinal CMS 5.1.0
Jfinal_cms 5.1.0 is vulnerable to SQL Injection via com.jflyfox.system.log.LogController.java.
network
low complexity
jflyfox CWE-89
6.5
2021-12-16 CVE-2021-37262 Injection vulnerability in Jflyfox Jfinal CMS 5.1.0
JFinal_cms 5.1.0 is vulnerable to regex injection that may lead to Denial of Service.
network
low complexity
jflyfox CWE-74
5.0
2021-09-15 CVE-2021-40639 Incorrect Authorization vulnerability in Jflyfox Jfinal CMS 5.1.0
Improper access control in Jfinal CMS 5.1.0 allows attackers to access sensitive information via /classes/conf/db.properties&config=filemanager.config.js.
network
low complexity
jflyfox CWE-863
5.0
2021-09-15 CVE-2020-19146 Path Traversal vulnerability in Jflyfox Jfinal CMS
Improper Access Control in Jfinal CMS v4.7.1 and earlier allows remote attackers to obtain sensitive information via the 'TemplatePath' parameter in the component 'jfinal_cms/admin/folder/list'.
network
low complexity
jflyfox CWE-22
4.0
2021-09-15 CVE-2020-19147 Path Traversal vulnerability in Jflyfox Jfinal CMS
Improper Access Control in Jfinal CMS v4.7.1 and earlier allows remote attackers to obtain sensitive infromation via the 'getFolder()' function in the component '/modules/filemanager/FileManager.java'.
network
low complexity
jflyfox CWE-22
4.0
2021-09-15 CVE-2020-19150 Path Traversal vulnerability in Jflyfox Jfinal CMS
Improper Access Control in Jfinal CMS v4.7.1 and earlier allows remote attackers to obtain sensitive information or cause a denial of service via the 'FileManager.delete()' function in the component 'modules/filemanager/FileManagerController.java'.
network
low complexity
jflyfox CWE-22
5.5
2021-09-15 CVE-2020-19151 Command Injection vulnerability in Jflyfox Jfinal CMS
Command Injection in Jfinal CMS v4.7.1 and earlier allows remote attackers to execute arbitrary code by uploading a malicious HTML template file via the component 'jfinal_cms/admin/filemanager/list'.
network
low complexity
jflyfox CWE-77
6.5
2021-09-15 CVE-2020-19154 Path Traversal vulnerability in Jflyfox Jfinal CMS
Improper Access Control in Jfinal CMS v4.7.1 and earlier allows remote attackers to obtain sensitive information via the 'FileManager.editFile()' function in the component 'modules/filemanager/FileManagerController.java'.
network
low complexity
jflyfox CWE-22
4.0