Description
JFinalCMS 1.0 is vulnerable to SQL Injection in rc/main/java/com/cms/entity/Content.java. The cause of the vulnerability is that the title parameter is controllable and is concatenated directly into filterSql without filtering.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-53697 | JFinalCMS 1.0 is vulnerable to SQL Injection in rc/main/java/com/cms/entity/Content.java. The cause of the vulnerability is that the title parameter is controllable and is concatenated directly into filterSql without filtering. |
References
History
Fri, 23 May 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Heyewei
Heyewei jfinalcms |
|
| CPEs | cpe:2.3:a:heyewei:jfinalcms:1.0:*:*:*:*:*:*:* | |
| Vendors & Products |
Heyewei
Heyewei jfinalcms |
Mon, 03 Feb 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-89 | |
| Metrics |
cvssV3_1
|
Wed, 29 Jan 2025 22:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | JFinalCMS 1.0 is vulnerable to SQL Injection in rc/main/java/com/cms/entity/Content.java. The cause of the vulnerability is that the title parameter is controllable and is concatenated directly into filterSql without filtering. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-02-03T19:22:21.662Z
Reserved: 2025-01-09T00:00:00.000Z
Link: CVE-2024-57665
Updated: 2025-02-03T19:22:16.592Z
Status : Analyzed
Published: 2025-01-29T23:15:22.597
Modified: 2025-05-23T14:50:35.920
Link: CVE-2024-57665
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD