PT-2023-30467 · Jflyfox · Jfinalcms

·

CVE-2023-47503

·

Published

2023-11-28

·

Updated

2023-12-02

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions jflyfox jfinalCMS version 5.1.0
Description The issue allows a remote attacker to execute arbitrary code via a crafted script to the "login.jsp" component in the template management module.
Recommendations For jflyfox jfinalCMS version 5.1.0, consider disabling access to the login.jsp component in the template management module until a patch is available. Restrict access to the template management module to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2023-47503

Affected Products

Jfinalcms