Description
A cross-site scripting (XSS) vulnerability in Jfinal CMS v5.1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted X-Forwarded-For request.
Remediation
References
https://github.com/jflyfox/jfinal_cms/issues/34
Related Vulnerabilities
CVE-2017-16090 Vulnerability in npm package fsk-server
CVE-2022-21213 Vulnerability in maven package org.webjars:mout
CVE-2023-26473 Vulnerability in maven package org.xwiki.platform:xwiki-platform-web-templates
CVE-2023-26158 Vulnerability in npm package mockjs
CVE-2021-32770 Vulnerability in npm package gatsby-source-wordpress