Description
JFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via /admin/slide/delete.
Remediation
References
https://github.com/li-yu320/cms/blob/main/There%20is%20a%20CSRF%20at%20the%20deletion%20point%20of%20the%20broadcast%20image.md
Related Vulnerabilities
CVE-2020-7693 Vulnerability in npm package sockjs
CVE-2023-36542 Vulnerability in maven package org.apache.nifi:nifi-hadoop-dbcp-service
CVE-2022-24377 Vulnerability in npm package cycle-import-check
CVE-2022-24897 Vulnerability in maven package org.xwiki.commons:xwiki-commons-velocity
CVE-2023-40037 Vulnerability in maven package org.apache.nifi:nifi-dbcp-service-api