Vulnerability CVE-2023-43192


Published: 2023-09-27   Modified: 2023-09-28

Description:
SQL injection can exist in a newly created part of the JFinalcms background, and the parameters submitted by users are not filtered. As a result, special characters in parameters destroy the original logic of SQL statements. Attackers can use this vulnerability to execute any SQL statement.

 References:
https://github.com/etn0tw/cve_sql/blob/main/jfinalcms_sql.md

Copyright 2026, cxsecurity.com

 

Back to Top