PT-2024-35755 · Jfinalcms · Jfinalcms

·

CVE-2024-53477

·

Published

2024-12-02

·

Updated

2024-12-11

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions JFinal CMS version 5.1.0
Description The issue concerns the unauthorized execution of deserialization in the ApiForm.java file, leading to command execution.
Recommendations For JFinal CMS version 5.1.0, consider disabling the deserialization functionality in the ApiForm.java file as a temporary workaround until a patch is available. Restrict access to the ApiForm.java file to minimize the risk of exploitation. Avoid using the deserialization feature in the affected version until the issue is resolved.

Exploit

Fix

Deserialization of Untrusted Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-53477

Affected Products

Jfinalcms