Description
A cross-site scripting (XSS) vulnerability in Jfinal CMS v5.1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted X-Forwarded-For request.
Remediation
References
https://github.com/jflyfox/jfinal_cms/issues/34
Related Vulnerabilities
CVE-2020-28480 Vulnerability in maven package org.webjars.bower:jointjs
CVE-2023-34238 Vulnerability in npm package gatsby-transformer-remark
CVE-2019-15477 Vulnerability in maven package org.jooby:jooby
CVE-2023-26158 Vulnerability in npm package mockjs
CVE-2020-13942 Vulnerability in maven package org.apache.unomi:unomi-services