CNNVD-202506-1850 Information

CNNVD ID

CNNVD-202506-1850

CVE-2025-6105

  • CNNVD Published: 2025-06-16

Description (Chinese)

jflyfox jfinal_cms是jflyfox开源的一个jfinal cms是一个java开发的功能强大的信息咨询网站,采用了简洁强大的JFinal作为web框架,模板引擎用的是beetl,数据库用mysql,前端bootstrap框架。支持oauth2认证、帐号注册、密码加密、评论及回复,消息提示,网站访问量统计,文章评论数和浏览量统计,回复管理,支持权限管理。后台模块包含:栏目管理,栏目公告,栏目滚动图片,文章管理,回复管理,意见反馈,我的相册,相册管理,图片管理,专辑管理、视频管理、缓存更新,友情链接,访问统计,联系人管理,模板管理,组织机构管理,用户管理,角色管理,菜单管理,数据字典管理。 jflyfox jfinal_cms 5.0.1版本存在安全漏洞,该漏洞源于跨站请求伪造问题,可能导致未授权操作。

Description (English)

jflybox jfinal cms is a jfinal cms, a jflyfox open source, a powerful information advisory website developed by java, using a simple and powerful Jfinal as a web framework, with a template engine using beetl, a database using mysql, front-end bootstream framework. Supports aauth2 authentication, account registration, password encryption, comments and responses, alerts, website access statistics, article review and browsing statistics, response management, and rights management. The back-office module contains: column management, column bulletins, column rolling pictures, article management, response management, feedback, my albums, album management, photo management, album management, video management, cache updating, friendship links, access statistics, contact management, template management, organizational management, user management, role management, menu management, data dictionary management. The jflyox jfinal cms 5.0.1 version has a security loophole, which stems from cross-site requests for forgery and may lead to unauthorized operations.

Hazard Level

High

Vulnerability Type

其他

Affected Vendor

jflyfox

Published

2025-06-16

Last Modified

2026-02-24

References

https://vuldb.com/?submit.590704 https://github.com/webzzaa/CVE-/issues/3 https://vuldb.com/?ctiid.312574 https://vuldb.com/?id.312574 https://access.redhat.com/security/cve/cve-2025-6105

Share on: