Description
Server-Side Template Injection (SSTI) vulnerability in jFinal v.4.9.08 allows a remote attacker to execute arbitrary code via the template function.
Remediation
References
https://github.com/jfinal/jfinal/issues/187
Related Vulnerabilities
CVE-2021-45046 Vulnerability in maven package org.apache.logging.log4j:log4j-core
CVE-2020-15168 Vulnerability in npm package node-fetch
CVE-2022-28355 Vulnerability in maven package org.scala-js:scalajs-library_2.13
CVE-2020-28443 Vulnerability in npm package sonar-wrapper
CVE-2020-13445 Vulnerability in maven package com.liferay:com.liferay.portal.template.freemarker