Description
A cross-site scripting (XSS) vulnerability in Jfinal CMS v5.1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted X-Forwarded-For request.
Remediation
References
https://github.com/jflyfox/jfinal_cms/issues/34
Related Vulnerabilities
CVE-2021-38294 Vulnerability in maven package org.apache.storm:storm-server
CVE-2017-16172 Vulnerability in npm package section2.madisonjbrooks12
CVE-2016-10735 Vulnerability in maven package com.loopeer.android:bootstrap
CVE-2023-26487 Vulnerability in npm package vega
CVE-2022-25758 Vulnerability in maven package org.webjars.npm:scss-tokenizer