Description
JFinalCMS v5.0.0 was discovered to contain a cross-site scripting (XSS) vulnerability in the model management department.
Remediation
References
https://github.com/Rabb1ter/cms/blob/main/There%20is%20a%20stored%20XSS%20in%20the%20model%20management%20department.md
Related Vulnerabilities
CVE-2016-10663 Vulnerability in npm package wixtoolset
CVE-2023-38704 Vulnerability in npm package import-in-the-middle
CVE-2019-10744 Vulnerability in maven package org.fujion.webjars:lodash
CVE-2020-36732 Vulnerability in maven package org.webjars.npm:crypto-js
CVE-2019-1353 Vulnerability in maven package org.webjars.npm:nodegit