Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2021-79736
HistorySep 16, 2021 - 12:00 a.m.

Jfinal cms improper access control vulnerability

2021-09-1600:00:00
China National Vulnerability Database
www.cnvd.org.cn
7

0.006 Low

EPSS

Percentile

77.9%

Jfinal CMS is a powerful information consulting website developed in java that uses JFinal as the web framework, beetl for the template engine, mysql for the database, and bootstrap framework for the front end. an improper access control vulnerability exists in Jfinal CMS 4.7.1 and earlier versions. An attacker can use the getFolder() function in /modules/filemanager/FileManager.java to obtain sensitive information.

CPENameOperatorVersion
jfinal cms jfinal cmsle4.7.1

0.006 Low

EPSS

Percentile

77.9%

Related for CNVD-2021-79736