Description
JFinal CMS 5.1.0 is vulnerable to SQL Injection via /jfinal_cms/system/user/list.
Remediation
References
https://github.com/jflyfox/jfinal_cms/issues/48
Related Vulnerabilities
CVE-2022-25940 Vulnerability in maven package org.webjars.npm:lite-server
CVE-2020-10591 Vulnerability in maven package com.walmartlabs.concord.server:concord-server-impl
CVE-2018-16492 Vulnerability in maven package org.webjars.npm:extend
CVE-2023-31582 Vulnerability in maven package org.bitbucket.b_c:jose4j
CVE-2022-21802 Vulnerability in maven package org.webjars.npm:grapesjs