Description
JFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/tag/update.
Remediation
References
https://github.com/cui2shark/cms/blob/main/Modification%20of%20CSRF%20in%20Label%20Management.md
Related Vulnerabilities
CVE-2012-0391 Vulnerability in maven package org.apache.struts.xwork:xwork-core
CVE-2022-45064 Vulnerability in maven package org.apache.sling:org.apache.sling.engine
CVE-2023-32697 Vulnerability in maven package org.xerial:sqlite-jdbc
CVE-2022-46769 Vulnerability in maven package org.apache.sling:org.apache.sling.cms.ui
CVE-2023-37954 Vulnerability in maven package com.sonyericsson.hudson.plugins.rebuild:rebuild