Description
JFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via admin/nav/delete.
Remediation
References
https://github.com/ysuzhangbin/cms/blob/main/CSRF%20exists%20at%20the%20deletion%20point%20of%20navigation%20management.md
Related Vulnerabilities
CVE-2023-24436 Vulnerability in maven package org.jenkins-ci.plugins:ghprb
CVE-2020-16022 Vulnerability in maven package org.webjars.npm:electron
CVE-2017-16103 Vulnerability in npm package serveryztyzt
CVE-2023-24429 Vulnerability in maven package org.jenkins-ci.plugins:semantic-versioning-plugin
CVE-2021-41269 Vulnerability in maven package com.cronutils:cron-utils