Vulnerabilities > Jflyfox > Medium

DATE CVE VULNERABILITY TITLE RISK
2021-09-15 CVE-2020-19154 Path Traversal vulnerability in Jflyfox Jfinal CMS
Improper Access Control in Jfinal CMS v4.7.1 and earlier allows remote attackers to obtain sensitive information via the 'FileManager.editFile()' function in the component 'modules/filemanager/FileManagerController.java'.
network
low complexity
jflyfox CWE-22
6.5