Description
Server-Side Template Injection (SSTI) vulnerability in jFinal v.4.9.08 allows a remote attacker to execute arbitrary code via the template function.
Remediation
References
https://github.com/jfinal/jfinal/issues/187
Related Vulnerabilities
CVE-2018-1000173 Vulnerability in maven package org.jenkins-ci.plugins:google-login
CVE-2019-19771 Vulnerability in npm package bconi
CVE-2023-26102 Vulnerability in npm package rangy
CVE-2020-8147 Vulnerability in npm package utils-extend
CVE-2022-43432 Vulnerability in maven package org.jenkins-ci.plugins:xframium