QID 981709
QID 981709: Java (maven) Security Update for com.jfinal:jfinal (GHSA-2c25-xfpq-8w9r)
An issue was discovered in JFinal framework v4.9.10 and below. The "set" method of the "Controller" class of jfinal framework is not strictly filtered, which will lead to XSS vulnerabilities in some cases.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-2c25-xfpq-8w9r for updates pertaining to this vulnerability.
Vendor References
- GHSA-2c25-xfpq-8w9r -
github.com/advisories/GHSA-2c25-xfpq-8w9r
CVEs related to QID 981709
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-2c25-xfpq-8w9r | com.jfinal:jfinal |
|