Description
JFinalcms 5.0.0 is vulnerable to Cross Site Scripting (XSS) via Label management editing.
Remediation
References
https://github.com/Jarvis-616/cms/blob/master/Label%20management%20editing%20with%20stored%20XSS.md
Related Vulnerabilities
CVE-2023-28155 Vulnerability in maven package org.webjars.bower:request
CVE-2022-0122 Vulnerability in npm package node-forge
CVE-2020-28282 Vulnerability in maven package org.webjars.npm:getobject
CVE-2023-33202 Vulnerability in maven package org.bouncycastle:bc-fips
CVE-2018-3739 Vulnerability in npm package https-proxy-agent