Description
Server-Side Template Injection (SSTI) vulnerability in jFinal v.4.9.08 allows a remote attacker to execute arbitrary code via the template function.
Remediation
References
https://github.com/jfinal/jfinal/issues/187
Related Vulnerabilities
CVE-2020-13445 Vulnerability in maven package com.liferay:com.liferay.portal.template.velocity
CVE-2023-34612 Vulnerability in maven package com.helger.commons:ph-json
CVE-2019-13506 Vulnerability in npm package @nuxtjs/devalue
CVE-2019-16772 Vulnerability in maven package org.webjars.npm:serialize-javascript
CVE-2022-31195 Vulnerability in maven package org.dspace:dspace-api