A vulnerability classified as problematic has been found in JFinalCMS up to 20221020. This affects an unknown part of the file /admin/content. The manipulation of the argument Title leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-266121 was assigned to this vulnerability.
History

Thu, 05 Jun 2025 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Heyewei
Heyewei jfinalcms
CPEs cpe:2.3:a:heyewei:jfinalcms:*:*:*:*:*:*:*:*
Vendors & Products Heyewei
Heyewei jfinalcms

cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published: 2024-05-24T09:00:09.357Z

Updated: 2024-08-01T21:11:12.418Z

Reserved: 2024-05-24T02:16:21.277Z

Link: CVE-2024-5310

cve-icon Vulnrichment

Updated: 2024-08-01T21:11:12.418Z

cve-icon NVD

Status : Analyzed

Published: 2024-05-24T09:15:09.337

Modified: 2025-06-05T20:03:12.757

Link: CVE-2024-5310

cve-icon Redhat

No data.