Description
A cross-site scripting (XSS) vulnerability in Jfinal CMS v5.1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted X-Forwarded-For request.
Remediation
References
https://github.com/jflyfox/jfinal_cms/issues/34
Related Vulnerabilities
CVE-2018-3738 Vulnerability in maven package org.webjars.npm:protobufjs
CVE-2024-1597 Vulnerability in maven package org.postgresql:postgresql
CVE-2021-32803 Vulnerability in npm package tar
CVE-2016-10531 Vulnerability in maven package org.webjars.npm:marked
CVE-2020-11998 Vulnerability in maven package org.apache.activemq:activemq-broker