Security
Headlines
HeadlinesLatestCVEs

Headline

GHSA-9pvq-4cc7-24jg: Cross-site Scripting in Jfinal CMS

Jfinal CMS v5.1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the keyword text field under the publish blog module.

ghsa
#xss#web#git

Cross-site Scripting in Jfinal CMS

Moderate severity GitHub Reviewed Published Jun 24, 2022 • Updated Jun 25, 2022

Related news

CVE-2022-33113: XSS vulnerability stored in the publish blog module of Jfinal_cms V5.1.0 · Issue #39 · jflyfox/jfinal_cms

Jfinal CMS v5.1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the keyword text field under the publish blog module.