Description
JFinalcms 5.0.0 is vulnerable to Cross Site Scripting (XSS) via Label management editing.
Remediation
References
https://github.com/Jarvis-616/cms/blob/master/Label%20management%20editing%20with%20stored%20XSS.md
Related Vulnerabilities
CVE-2010-1622 Vulnerability in maven package org.springframework:spring-beans
CVE-2023-26480 Vulnerability in maven package org.xwiki.platform:xwiki-platform-livedata-webjar
CVE-2023-26108 Vulnerability in npm package @nestjs/core
CVE-2020-26302 Vulnerability in maven package org.webjars.bower:is_js
CVE-2022-34114 Vulnerability in maven package io.dataease:dataease-plugin-common