SQL Injection Vulnerability in JFinal CMS by JFlyFox
CVE-2022-38279
7.2HIGH
What is CVE-2022-38279?
The JFinal CMS version 5.1.0 presents a vulnerability that allows attackers to execute SQL injection via the /admin/imagealbum/list endpoint. This flaw can be exploited to manipulate database queries, potentially leading to unauthorized access to sensitive information or data corruption. It is crucial for users of JFinal CMS to apply security best practices and update to a patched version to mitigate these risks.
