Headline
GHSA-9pvq-4cc7-24jg: Cross-site Scripting in Jfinal CMS
Jfinal CMS v5.1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the keyword text field under the publish blog module.
Cross-site Scripting in Jfinal CMS
Moderate severity GitHub Reviewed Published Jun 24, 2022 • Updated Jun 25, 2022
Related news
CVE-2022-33113: XSS vulnerability stored in the publish blog module of Jfinal_cms V5.1.0 · Issue #39 · jflyfox/jfinal_cms
Jfinal CMS v5.1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the keyword text field under the publish blog module.