Description
JFinalcms 5.0.0 is vulnerable to Cross Site Scripting (XSS) via carousel image editing.
Remediation
References
https://github.com/Jarvis-616/cms/blob/master/There%20is%20a%20storage%20type%20XSS%20for%20carousel%20image%20editing.md
Related Vulnerabilities
CVE-2023-3691 Vulnerability in maven package org.webjars.bowergithub.sentsin:layui
CVE-2016-10531 Vulnerability in maven package org.webjars.npm:marked
CVE-2020-14968 Vulnerability in maven package org.webjars.npm:jsrsasign
CVE-2020-12668 Vulnerability in maven package com.hubspot.jinjava:jinjava
CVE-2013-1814 Vulnerability in maven package org.apache.rave:rave-web