Description
JFinalCMS 5.0.0 could allow a remote attacker to read files via ../ Directory Traversal in the /common/down/file fileKey parameter.
Remediation
References
https://gitee.com/heyewei/JFinalcms/issues/I7WGC6
Related Vulnerabilities
CVE-2020-27428 Vulnerability in npm package scratch-svg-renderer
CVE-2023-3308 Vulnerability in maven package com.whaleal.icefrog:icefrog-all
CVE-2023-37955 Vulnerability in maven package org.jenkins-ci.plugins:test-results-aggregator
CVE-2021-23771 Vulnerability in npm package notevil
CVE-2022-24847 Vulnerability in maven package org.geoserver.web:gs-web-sec-jdbc