Description
JFinalcms 5.0.0 is vulnerable to Cross Site Scripting (XSS) via carousel image editing.
Remediation
References
https://github.com/Jarvis-616/cms/blob/master/There%20is%20a%20storage%20type%20XSS%20for%20carousel%20image%20editing.md
Related Vulnerabilities
CVE-2020-7716 Vulnerability in npm package deeps
CVE-2019-16728 Vulnerability in maven package org.webjars.bowergithub.cure53:dompurify
CVE-2020-11023 Vulnerability in npm package jquery
CVE-2022-1365 Vulnerability in npm package cross-fetch
CVE-2022-23059 Vulnerability in maven package com.shopizer:shopizer