CVE-2022-37208
Summary
| CVE | CVE-2022-37208 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-10-13 12:15:00 UTC |
| Updated | 2022-10-13 13:02:00 UTC |
| Description | JFinal CMS 5.1.0 is vulnerable to SQL Injection. These interfaces do not use the same component, nor do they have filters, but each uses its own SQL concatenation method, resulting in SQL injection. |
Risk And Classification
Problem Types: CWE-89
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Jflyfox | Jfinal Cms | 5.1.0 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| someEXP_of_jfinal_cms/sql5.md at main · AgainstTheLight/someEXP_of_jfinal_cms · GitHub | MISC | github.com | Exploit, Third Party Advisory |
| GitHub - AgainstTheLight/CVE-2022-37208: CVE-2022-37208 | MISC | github.com | Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.