Description
JFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/tag/delete.
Remediation
References
https://github.com/cui2shark/cms/blob/main/Delete%20existing%20CSRF%20in%20label%20management.md
Related Vulnerabilities
CVE-2023-24458 Vulnerability in maven package org.jenkins-ci.plugins:bearychat
CVE-2013-7250 Vulnerability in maven package org.projectforge:projectforge-webapp
CVE-2023-29471 Vulnerability in maven package com.typesafe.akka:akka-stream-kafka_3
CVE-2023-37954 Vulnerability in maven package com.sonyericsson.hudson.plugins.rebuild:rebuild
CVE-2023-40815 Vulnerability in maven package org.opencrx:opencrx-core-models