Description
JFinalcms 5.0.0 is vulnerable to Cross Site Scripting (XSS) via Label management editing.
Remediation
References
https://github.com/Jarvis-616/cms/blob/master/Label%20management%20editing%20with%20stored%20XSS.md
Related Vulnerabilities
CVE-2016-10538 Vulnerability in maven package org.webjars.npm:cli
CVE-2018-15890 Vulnerability in maven package org.ethereum:ethereumj-core
CVE-2020-16040 Vulnerability in maven package org.webjars.npm:electron
CVE-2021-21179 Vulnerability in npm package electron
CVE-2020-7679 Vulnerability in maven package org.webjars.bower:casperjs