Skip to content
Permalink
main
Switch branches/tags

Name already in use

A tag already exists with the provided branch name. Many Git commands accept both tag and branch names, so creating this branch may cause unexpected behavior. Are you sure you want to create this branch?
Go to file
 
 
Cannot retrieve contributors at this time

CVE-2022-37204

CVE-2022-37204 POC

[Suggested description] ** RESERVED **JFinal CMS 5.1.0 is vulnerable to SQL Injection.


[Additional Information] https://github.com/AgainstTheLight/someEXP_of_jfinal_cms/blob/main/jfinal_cms/sql7.md


[Vulnerability Type] SQL Injection


[Vendor of Product] the development group


[Affected Product Code Base] https://github.com/jflyfox/jfinal_cms - JFinal CMS 5.1.0


[Affected Component] These interfaces do not use the same component, nor do they have filters, but each uses its own SQL concatenation method, resulting in SQL injection


[Attack Type] Remote


[Impact Code execution] true


[Impact Information Disclosure] true


[Attack Vectors] User login is required


[Reference] https://github.com/AgainstTheLight/someEXP_of_jfinal_cms/blob/main/jfinal_cms/sql7.md


[Discoverer] jw5t