CVE-2024-57665

Severity CVSS v4.0:
Pending analysis
Type:
CWE-89 SQL Injection
Publication date:
29/01/2025
Last modified:
23/05/2025

Description

JFinalCMS 1.0 is vulnerable to SQL Injection in rc/main/java/com/cms/entity/Content.java. The cause of the vulnerability is that the title parameter is controllable and is concatenated directly into filterSql without filtering.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:heyewei:jfinalcms:1.0:*:*:*:*:*:*:*