CVE-2023-43192 Information
Sep 30, 2023
cve
Description
SQL injection can exist in a newly created part of the JFinalcms background and the parameters submitted by users are not filtered. As a result special characters in parameters destroy the original logic of SQL statements. Attackers can use this vulnerability to execute any SQL statement.
Reference
https://github.com/etn0tw/cve_sql/blob/main/jfinalcms_sql.md
Share on: