Description
Server-Side Template Injection (SSTI) vulnerability in jFinal v.4.9.08 allows a remote attacker to execute arbitrary code via the template function.
Remediation
References
https://github.com/jfinal/jfinal/issues/187
Related Vulnerabilities
CVE-2022-4742 Vulnerability in npm package json-pointer
CVE-2013-2115 Vulnerability in maven package org.apache.struts:struts2-core
CVE-2019-20444 Vulnerability in maven package io.netty:netty-all
CVE-2022-35915 Vulnerability in maven package org.webjars.npm:openzeppelin__contracts
CVE-2021-21391 Vulnerability in npm package @ckeditor/ckeditor5-font