An issue in jflyfox jfinalCMS v.5.1.0 allows a remote attacker to execute arbitrary code via a crafted script to the login.jsp component in the template management module.
Affected Software
| Name | Vendor | Start Version | End Version |
|---|
| Jfinal_cms | Jflyfox | 5.1.0 (including) | 5.1.0 (including) |
References