Impact
The vulnerability resides in the AdvicefeedbackController.java list function of jflyfox jfinal_cms. By manipulating the orderBy argument, an attacker can inject arbitrary SQL. This type of injection can allow unauthorized reading or modification of the underlying database, potentially compromising confidentiality, integrity, or availability, depending on the database contents.
Affected Systems
The flaw affects jflyfox jfinal_cms versions up to and including 5.1.0. This encompasses all deployments of the CMS built with these releases.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. The EPSS score is not available, and the vulnerability is not listed in CISA KEV. Attackers can launch the exploit remotely by sending crafted requests to the service. The lack of a publicly available patch means that any system still running an affected version remains at risk until an update is applied.
OpenCVE Enrichment