An issue in jflyfox jfinalCMS v.5.1.0 allows a remote attacker to execute arbitrary code via a crafted script to the login.jsp component in the template management module.
Affected Software
Name |
Vendor |
Start Version |
End Version |
Jfinal_cms |
Jflyfox |
5.1.0 (including) |
5.1.0 (including) |
References