📦 Jfinaloa

by Jfinaloa Project

🔍 What is Jfinaloa?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2024-57768

CRITICAL CVSS 9.8 Jan 16, 2025

This SQL injection vulnerability in JFinalOA allows attackers to execute arbitrary SQL commands through the validRoleKey parameter. It affects all systems running JFinalOA versions before 2025.01.01, ...

CVE-2024-57775

HIGH CVSS 8.8 Jan 16, 2025

This SQL injection vulnerability in JFinalOA allows attackers to execute arbitrary SQL commands through the getWorkFlowHis?insid component. It affects all users running JFinalOA versions before 2025.0...

CVE-2024-57770

HIGH CVSS 8.8 Jan 16, 2025

This SQL injection vulnerability in JFinalOA allows attackers to execute arbitrary SQL commands through the contract application component. It affects all organizations using JFinalOA versions before ...

CVE-2024-57773

MEDIUM CVSS 4.8 Jan 16, 2025

This cross-site scripting (XSS) vulnerability in JFinalOA allows attackers to inject malicious scripts into the openSelectManyUserPage interface. When exploited, it enables execution of arbitrary Java...

CVE-2024-57776

MEDIUM CVSS 4.6 Jan 16, 2025

This cross-site scripting (XSS) vulnerability in JFinalOA allows attackers to inject malicious scripts into the /apply/getEditPage?view interface. When exploited, it enables execution of arbitrary Jav...

CVE-2024-57771

MEDIUM CVSS 4.8 Jan 16, 2025

This cross-site scripting (XSS) vulnerability in JFinalOA allows attackers to inject malicious scripts into the common/getEditPage?view interface. When exploited, it enables execution of arbitrary web...