Description
JFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/category/delete.
Remediation
References
https://github.com/nightcloudos/new_cms/blob/main/CSRF%20exists%20at%20the%20deletion%20point%20of%20column%20management.md
Related Vulnerabilities
CVE-2023-24977 Vulnerability in maven package org.apache.inlong:manager-pojo
CVE-2023-35148 Vulnerability in maven package org.jenkins-ci.plugins:ease-plugin
CVE-2020-8123 Vulnerability in npm package strapi
CVE-2010-2076 Vulnerability in maven package org.apache.cxf:cxf-bundle-jaxrs
CVE-2020-26870 Vulnerability in maven package org.webjars.bower:dompurify