CVE-2023-43192 Information

Description

SQL injection can exist in a newly created part of the JFinalcms background and the parameters submitted by users are not filtered. As a result special characters in parameters destroy the original logic of SQL statements. Attackers can use this vulnerability to execute any SQL statement.

Reference

https://github.com/etn0tw/cve_sql/blob/main/jfinalcms_sql.md

Share on: