CVE-2022-37208# 37208
CVE-2022-37208
> [Suggested description]
> JFinal CMS 5.1.0 is vulnerable to SQL Injection. These interfaces do
> not use the same component, nor do they have filters, but each uses its
> own SQL concatenation method, resulting in SQL injection.
>
> ------------------------------------------
>
> [Additional Information]
> https://github.com/AgainstTheLight/someEXP_of_jfinal_cms/blob/main/jfinal_cms/sql5.md
>
> ------------------------------------------
>
> [Vulnerability Type]
> SQL Injection
>
> ------------------------------------------
>
> [Vendor of Product]
> the development group
>
> ------------------------------------------
>
> [Affected Product Code Base]
> https://github.com/jflyfox/jfinal_cms - JFinal CMS 5.1.0
>
> ------------------------------------------
>
> [Affected Component]
> These interfaces do not use the same component, nor do they have filters, but each uses its own SQL concatenation method, resulting in SQL injection
>
> ------------------------------------------
>
> [Attack Type]
> Remote
>
> ------------------------------------------
>
> [Impact Code execution]
> true
>
> ------------------------------------------
>
> [Impact Information Disclosure]
> true
>
> ------------------------------------------
>
> [Attack Vectors]
> User login is required
>
> ------------------------------------------
>
> [Reference]
> https://github.com/AgainstTheLight/someEXP_of_jfinal_cms/blob/main/jfinal_cms/sql5.md
>
> ------------------------------------------
>
> [Discoverer]
> jw5t
Use CVE-2022-37208.
[4.0K] /data/pocs/2aec2e65c3fdae588eb345e9cf6c61f5380a1a37
├── [ 11K] LICENSE
└── [1.5K] README.md
0 directories, 2 files