Vulnerabilities > Jflyfox > Medium

DATE CVE VULNERABILITY TITLE RISK
2023-04-05 CVE-2023-24747 Cross-site Scripting vulnerability in Jflyfox Jfinal CMS 5.1
Jfinal CMS v5.1 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /system/dict/list.
network
low complexity
jflyfox CWE-79
5.4
2023-02-03 CVE-2023-22975 Cross-site Scripting vulnerability in Jflyfox Jfinal CMS 5.1.0
A cross-site scripting (XSS) vulnerability in JFinal CMS v5.1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the email parameter under /front/person/profile.html.
network
low complexity
jflyfox CWE-79
6.1
2022-08-25 CVE-2022-36527 Cross-site Scripting vulnerability in Jflyfox Jfinal CMS 5.1.0
Jfinal CMS v5.1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the post title text field under the publish blog module.
network
low complexity
jflyfox CWE-79
5.4
2022-06-23 CVE-2022-33113 Cross-site Scripting vulnerability in Jflyfox Jfinal CMS 5.1.0
Jfinal CMS v5.1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the keyword text field under the publish blog module.
network
low complexity
jflyfox CWE-79
5.4
2022-06-02 CVE-2022-29648 Cross-site Scripting vulnerability in Jflyfox Jfinal CMS 5.1.0
A cross-site scripting (XSS) vulnerability in Jfinal CMS v5.1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted X-Forwarded-For request.
network
low complexity
jflyfox CWE-79
5.4
2022-04-11 CVE-2022-27111 Cross-site Scripting vulnerability in Jflyfox Jfinal CMS 5.1.0
Jfinal_CMS 5.1.0 allows attackers to use the feedback function to send malicious XSS code to the administrator backend and execute it.
network
low complexity
jflyfox CWE-79
5.4
2022-01-25 CVE-2021-46087 Cross-site Scripting vulnerability in Jflyfox Jfinal CMS 5.1.0
In jfinal_cms >= 5.1 0, there is a storage XSS vulnerability in the background system of CMS.
network
low complexity
jflyfox CWE-79
5.4
2021-09-15 CVE-2020-19146 Path Traversal vulnerability in Jflyfox Jfinal CMS
Improper Access Control in Jfinal CMS v4.7.1 and earlier allows remote attackers to obtain sensitive information via the 'TemplatePath' parameter in the component 'jfinal_cms/admin/folder/list'.
network
low complexity
jflyfox CWE-22
6.5
2021-09-15 CVE-2020-19147 Path Traversal vulnerability in Jflyfox Jfinal CMS
Improper Access Control in Jfinal CMS v4.7.1 and earlier allows remote attackers to obtain sensitive infromation via the 'getFolder()' function in the component '/modules/filemanager/FileManager.java'.
network
low complexity
jflyfox CWE-22
6.5
2021-09-15 CVE-2020-19148 Cross-site Scripting vulnerability in Jflyfox Jfinal CMS
Cross Site Scripting (XSS) in Jfinal CMS v4.7.1 and earlier allows remote attackers to execute arbitrary code via the 'Nickname' parameter in the component '/jfinal_cms/front/person/profile.html'.
network
low complexity
jflyfox CWE-79
5.4