Sploitus

CVE-2022-37208

1 known exploit for CVE-2022-37208

JFinal CMS 5.1.0 is vulnerable to SQL Injection. These interfaces do not use the same component, nor do they have filters, but each uses its own SQL concatenation method, resulting in SQL injection.

Affected products
Jfinalcms
Jflyfox Jfinal Cms
= 5.1.0
CVSS 3.1
8.8 HIGH
EPSS
1.1% (63th percentile)
Weakness
CWE-89
NVD status
Modified
Published
2022-10-13
CVE-2022-37208 at NVD
Authoritative description, scoring and affected products

1 known exploit for CVE-2022-37208

Proof-of-concept code and exploit modules indexed by Sploitus