SQL Injection Vulnerability in JFinal CMS by JFlyfox
CVE-2022-38280
7.2HIGH
What is CVE-2022-38280?
JFinal CMS version 5.1.0 contains a vulnerability that allows attackers to exploit SQL Injection through the /admin/image/list endpoint. This weakness could enable unauthorized access to the database, allowing attackers to manipulate queries to gain sensitive data or perform unintended actions. Organizations using this version should take immediate action to secure their systems by applying necessary patches or updates.
