SQL Injection Vulnerability in JFinal CMS by JFlyFox
CVE-2022-38272
7.2HIGH
What is CVE-2022-38272?
JFinal CMS version 5.1.0 contains a vulnerability that allows for SQL Injection through the endpoint /admin/article/list. This flaw enables attackers to execute arbitrary SQL queries through crafted input, potentially compromising the database and exposing sensitive information. Proper input validation and use of prepared statements are recommended to mitigate this issue.
