Description
Jfinal CMS v5.1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the post title text field under the publish blog module.
Remediation
References
https://github.com/jflyfox/jfinal_cms/issues/45
Related Vulnerabilities
CVE-2020-7721 Vulnerability in npm package node-oojs
CVE-2021-43306 Vulnerability in maven package org.webjars.bower:jquery-validation
CVE-2011-0013 Vulnerability in maven package org.apache.tomcat.embed:tomcat-embed-core
CVE-2021-44906 Vulnerability in maven package org.webjars.npm:minimist
CVE-2020-6428 Vulnerability in maven package org.webjars.npm:electron