Description
Server-Side Template Injection (SSTI) vulnerability in jFinal v.4.9.08 allows a remote attacker to execute arbitrary code via the template function.
Remediation
References
https://github.com/jfinal/jfinal/issues/187
Related Vulnerabilities
CVE-2022-42466 Vulnerability in maven package org.apache.isis.viewer:isis-viewer-wicket-ui
CVE-2022-36537 Vulnerability in maven package org.zkoss.zk:zk
CVE-2022-37264 Vulnerability in npm package steal
CVE-2020-26217 Vulnerability in maven package xstream:xstream
CVE-2023-31582 Vulnerability in maven package org.bitbucket.b_c:jose4j