PT-2023-20805 · Jfinalcms · Jfinalcms
CVE-2023-26812
·
Publicado
2023-04-28
·
Atualizado
2023-05-02
Nenhuma
Não há classificações de severidade ou métricas disponíveis. Quando houver, atualizaremos as informações correspondentes na página.
Name of the Vulnerable Software and Affected Versions
jfinal CMS version 5.1.0
Description
A command execution issue in the ActionEnter Class of jfinal CMS allows attackers to execute arbitrary code via a created json file to the ueditor route.
Recommendations
For jfinal CMS version 5.1.0, consider disabling the ActionEnter Class or restricting access to the ueditor route until a patch is available.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Jfinalcms