CVE-2021-33348
Summary
| CVE | CVE-2021-33348 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-06-24 15:15:00 UTC |
| Updated | 2021-06-30 20:29:00 UTC |
| Description | An issue was discovered in JFinal framework v4.9.10 and below. The "set" method of the "Controller" class of jfinal framework is not strictly filtered, which will lead to XSS vulnerabilities in some cases. |
Risk And Classification
Problem Types: CWE-79
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| There are XSS vulnerabilities in some cases · Issue #188 · jfinal/jfinal · GitHub | MISC | github.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 981709 Java (maven) Security Update for com.jfinal:jfinal (GHSA-2c25-xfpq-8w9r)