Security
Headlines
HeadlinesLatestCVEs

Headline

GHSA-gh24-c683-79r2: Arbitrary code execution in jfinal CMS

Command execution vulnerability in the ActionEnter Class ins jfinal CMS version 5.1.0 allows attackers to execute arbitrary code via a created json file to the ueditor route.

ghsa
#vulnerability#js#git

Arbitrary code execution in jfinal CMS

Critical severity GitHub Reviewed Published Apr 28, 2023 to the GitHub Advisory Database • Updated May 1, 2023

ghsa: Latest News

GHSA-vfpf-xmwh-8m65: ProsemirrorToHtml has a Cross-Site Scripting (XSS) vulnerability through unescaped HTML attribute values