Description
Server-Side Template Injection (SSTI) vulnerability in jFinal v.4.9.08 allows a remote attacker to execute arbitrary code via the template function.
Remediation
References
https://github.com/jfinal/jfinal/issues/187
Related Vulnerabilities
CVE-2020-7746 Vulnerability in maven package org.webjars.bowergithub.chartjs:chart.js
CVE-2020-7748 Vulnerability in npm package @tsed/core
CVE-2020-7624 Vulnerability in npm package effect
CVE-2020-2169 Vulnerability in maven package org.jenkins-ci.plugins:queue-cleanup
CVE-2021-43570 Vulnerability in maven package com.starkbank.ellipticcurve:starkbank-ecdsa