Description
A cross-site scripting (XSS) vulnerability in Jfinal CMS v5.1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted X-Forwarded-For request.
Remediation
References
https://github.com/jflyfox/jfinal_cms/issues/34
Related Vulnerabilities
CVE-2021-23430 Vulnerability in npm package startserver
CVE-2017-14949 Vulnerability in maven package org.restlet.osgi:org.restlet
CVE-2023-24057 Vulnerability in maven package ca.uhn.hapi.fhir:org.hl7.fhir.r4b
CVE-2022-4111 Vulnerability in npm package tooljet
CVE-2021-29441 Vulnerability in maven package com.alibaba.nacos:nacos-common