This advisory has been withdrawn because it is a duplicate of GHSA-8qhm-ch8h-xgjr. This link is maintained to preserve external references.
Command execution vulnerability in the ActionEnter Class ins jfinal CMS version 5.1.0 allows attackers to execute arbitrary code via a created json file to the ueditor route.
{
"cwe_ids": [],
"github_reviewed": true,
"github_reviewed_at": "2023-05-01T14:01:21Z",
"nvd_published_at": "2023-04-28T20:15:13Z",
"severity": "CRITICAL"
}