Description
JFinal CMS 5.1.0 is vulnerable to SQL Injection via /jfinal_cms/system/user/list.
Remediation
References
https://github.com/jflyfox/jfinal_cms/issues/48
Related Vulnerabilities
CVE-2022-29546 Vulnerability in maven package org.codelibs:nekohtml
CVE-2023-33544 Vulnerability in maven package io.hawt:hawtio-system
CVE-2022-45206 Vulnerability in maven package org.jeecgframework.boot:jeecg-boot-base-core
CVE-2022-23496 Vulnerability in maven package nl.basjes.parse.useragent:yauaa-elastic-udfs-parent
CVE-2020-13957 Vulnerability in maven package org.apache.solr:solr-core