Description
JFinalCMS v5.0.0 was discovered to contain a cross-site scripting (XSS) vulnerability in the model management department.
Remediation
References
https://github.com/Rabb1ter/cms/blob/main/There%20is%20a%20stored%20XSS%20in%20the%20model%20management%20department.md
Related Vulnerabilities
CVE-2022-24728 Vulnerability in npm package ckeditor4
CVE-2020-22864 Vulnerability in npm package froala-editor
CVE-2020-26291 Vulnerability in maven package org.webjars.npm:urijs
CVE-2021-23362 Vulnerability in maven package org.webjars.npm:hosted-git-info
CVE-2018-16487 Vulnerability in npm package lodash.defaultsdeep