Description
Server-Side Template Injection (SSTI) vulnerability in jFinal v.4.9.08 allows a remote attacker to execute arbitrary code via the template function.
Remediation
References
https://github.com/jfinal/jfinal/issues/187
Related Vulnerabilities
CVE-2020-7610 Vulnerability in npm package bson
CVE-2023-3691 Vulnerability in maven package org.webjars.bowergithub.sentsin:layui
CVE-2020-2153 Vulnerability in maven package org.jenkins-ci.plugins:backlog
CVE-2014-6071 Vulnerability in maven package org.webjars:jquery
CVE-2020-14968 Vulnerability in maven package org.webjars.npm:jsrsasign