SQL Injection Vulnerability in JFinal CMS by JFlyFox
CVE-2022-38277
7.2HIGH
What is CVE-2022-38277?
JFinal CMS 5.1.0 is susceptible to SQL Injection through the endpoint /admin/folderrollpicture/list, which enables attackers to manipulate database queries. This vulnerability can allow unauthorized access to sensitive information, posing a risk to the integrity and confidentiality of the data managed by the CMS. It's crucial for administrators to apply security patches and validate inputs to mitigate potential exploitation.
