CVEs Blog | G5 Cyber Security

CVE-2020-19146 – Improper Access Control in Jfinal CMS v4.7.1 and earlier allows remote at

Improper Access Control in Jfinal CMS v4.7.1 and earlier allows remote attackers to obtain sensitive information via the ‘TemplatePath’ parameter in the component ‘jfinal_cms/admin/folder/list’.

 

Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-19146

Reference (s):

Exit mobile version