SQL Injection Vulnerability in JFinal CMS by JFlyFox
CVE-2022-38284
7.2HIGH
What is CVE-2022-38284?
JFinal CMS version 5.1.0 contains a vulnerability that allows intruders to execute unauthorized SQL commands via the /system/department/list endpoint. This could potentially enable attackers to access, manipulate, or delete sensitive data stored within the database, jeopardizing the integrity and confidentiality of the application's information.
