Exploitation Summary
EIP tracks 1 public exploit for CVE-2022-37201. PoCs published by AgainstTheLight.
AI-analyzed exploit summary This repository provides a functional SQL injection exploit for CVE-2022-37201 in JFinal CMS 5.1.0, leveraging sqlmap to exploit an order-by SQL injection vulnerability in the /admin/contact/list endpoint. The README includes technical details, a working sqlmap command, and a raw HTTP request for testing.
Description
JFinal CMS 5.1.0 is vulnerable to SQL Injection.
Exploits (1)
This repository provides a functional SQL injection exploit for CVE-2022-37201 in JFinal CMS 5.1.0, leveraging sqlmap to exploit an order-by SQL injection vulnerability in the /admin/contact/list endpoint. The README includes technical details, a working sqlmap command, and a raw HTTP request for testing.
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H