Description
Server-Side Template Injection (SSTI) vulnerability in jFinal v.4.9.08 allows a remote attacker to execute arbitrary code via the template function.
Remediation
References
https://github.com/jfinal/jfinal/issues/187
Related Vulnerabilities
CVE-2017-14063 Vulnerability in maven package org.asynchttpclient:async-http-client-project
CVE-2020-15842 Vulnerability in maven package com.liferay:com.liferay.portal.template.freemarker
CVE-2023-29471 Vulnerability in maven package com.typesafe.akka:akka-stream-kafka_3
CVE-2022-45388 Vulnerability in maven package net.praqma:config-rotator
CVE-2012-6153 Vulnerability in maven package org.apache.httpcomponents:httpclient