GHSA-gh24-c683-79r2

Suggest an improvement
Source
https://github.com/advisories/GHSA-gh24-c683-79r2
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/04/GHSA-gh24-c683-79r2/GHSA-gh24-c683-79r2.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-gh24-c683-79r2
Aliases
  • CVE-2023-26812
Withdrawn
2023-05-03T18:17:25Z
Published
2023-04-28T21:30:19Z
Modified
2026-09-10T03:50:00Z
Summary
Duplicate Advisory: Arbitrary code execution in jfinal CMS
Details

Duplicate Advisory

This advisory has been withdrawn because it is a duplicate of GHSA-8qhm-ch8h-xgjr. This link is maintained to preserve external references.

Original Description

Command execution vulnerability in the ActionEnter Class ins jfinal CMS version 5.1.0 allows attackers to execute arbitrary code via a created json file to the ueditor route.

Database specific
{
    "cwe_ids": [],
    "github_reviewed": true,
    "github_reviewed_at": "2023-05-01T14:01:21Z",
    "nvd_published_at": "2023-04-28T20:15:13Z",
    "severity": "CRITICAL"
}
References

Affected packages

Maven / com.jflyfox:jflyfox_jfinal

Package

Name
com.jflyfox:jflyfox_jfinal
View open source insights on deps.dev
Purl
pkg:maven/com.jflyfox/jflyfox_jfinal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Last Affected
5.1.0

Affected versions

1.*
1.8
1.9
2.*
2.0
2.1
3.*
3.0
4.*
4.0
4.1
4.2
4.3
4.4
4.5.0

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/04/GHSA-gh24-c683-79r2/GHSA-gh24-c683-79r2.json"