Jfinaloa ProjectCVEs & Vulnerabilities

11 CVEs affecting Jfinaloa Project products, tracked from the National Vulnerability Database, with CVSS/EPSS scores and exploitation status.

Most Affected Products

jfinaloa 11
CVE-2024-57776MEDIUM

A cross-site scripting (XSS) vulnerability in the /apply/getEditPage?view interface of JFinalOA before v2025.01.01 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.

16 Jan 2025
4.6
CVSS
CVE-2024-57775HIGH

JFinalOA before v2025.01.01 was discovered to contain a SQL injection vulnerability via the component getWorkFlowHis?insid.

16 Jan 2025
8.8
CVSS
CVE-2024-57774MEDIUM

A cross-site scripting (XSS) vulnerability in the getBusinessUploadListPage?busid interface of JFinalOA before v2025.01.01 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.

16 Jan 2025
4.8
CVSS
CVE-2024-57773MEDIUM

A cross-site scripting (XSS) vulnerability in the openSelectManyUserPage?orgid interface of JFinalOA before v2025.01.01 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.

16 Jan 2025
4.8
CVSS
CVE-2024-57772MEDIUM

A cross-site scripting (XSS) vulnerability in the /bumph/getDraftListPage?type interface of JFinalOA before v2025.01.01 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.

16 Jan 2025
4.8
CVSS
CVE-2024-57771MEDIUM

A cross-site scripting (XSS) vulnerability in the common/getEditPage?view interface of JFinalOA before v2025.01.01 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.

16 Jan 2025
4.8
CVSS
CVE-2024-57770HIGH

JFinalOA before v2025.01.01 was discovered to contain a SQL injection vulnerability via the component apply/save#oaContractApply.id.

16 Jan 2025
8.8
CVSS
CVE-2024-57769HIGH

JFinalOA before v2025.01.01 was discovered to contain a SQL injection vulnerability via the component borrowmoney/listData?applyUser.

16 Jan 2025
8.8
CVSS
CVE-2024-57768CRITICAL

JFinalOA before v2025.01.01 was discovered to contain a SQL injection vulnerability via the component validRoleKey?sysRole.key.

16 Jan 2025
9.8
CVSS
CVE-2023-0758CRITICAL

A vulnerability was found in glorylion JFinalOA 1.0.2 and classified as critical. This issue affects some unknown processing of the file src/main/java/com/pointlion/mvc/common/model/SysOrg.java. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-220469 was assigned to this vulnerability.

9 Feb 2023
9.8
CVSS
CVE-2021-40645MEDIUM

An SQL Injection vulnerability exists in glorylion JFinalOA as of 9/7/2021 in the defkey parameter getHaveDoneTaskDataList method of the FlowTaskController.

31 Mar 2022
6.5
CVSS
← PrevPage 1 / 1Next →
Jfinaloa Project CVEs & Vulnerabilities — 11 Tracked