CVE-2022-37203
Summary
| CVE | CVE-2022-37203 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-09-19 16:15:00 UTC |
| Updated | 2022-09-21 17:40:00 UTC |
| Description | JFinal CMS 5.1.0 is vulnerable to SQL Injection. These interfaces do not use the same component, nor do they have filters, but each uses its own SQL concatenation method, resulting in SQL injection. |
Risk And Classification
Problem Types: CWE-89
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Jflyfox | Jfinal Cms | 5.1.0 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| CVE-2022-37203/README.md at main · AgainstTheLight/CVE-2022-37203 · GitHub | MISC | github.com | |
| someEXP_of_jfinal_cms/sql3.md at main · AgainstTheLight/someEXP_of_jfinal_cms · GitHub | MISC | github.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.