CVE-2022-37203

CRITICAL

JFinal CMS 5.1.0 - SQL Injection

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2022-37203. PoCs published by AgainstTheLight.

AI-analyzed exploit summary This repository provides a technical writeup for CVE-2022-37203, detailing a SQL injection vulnerability in JFinal CMS 5.1.0. It references external documentation and outlines the impact, including code execution, privilege escalation, and information disclosure.

Description

JFinal CMS 5.1.0 is vulnerable to SQL Injection. These interfaces do not use the same component, nor do they have filters, but each uses its own SQL concatenation method, resulting in SQL injection.

Exploits (1)

nomisec WRITEUP
by AgainstTheLight · poc
https://github.com/AgainstTheLight/CVE-2022-37203

This repository provides a technical writeup for CVE-2022-37203, detailing a SQL injection vulnerability in JFinal CMS 5.1.0. It references external documentation and outlines the impact, including code execution, privilege escalation, and information disclosure.

Classification
Writeup 80%
Attack Type
Sqli
Complexity
Moderate
Reliability
Theoretical
Target: JFinal CMS 5.1.0
No auth needed
Prerequisites: Access to the affected JFinal CMS instance
devstral-2 · analyzed Feb 18, 2026 Full analysis →

Scores

CVSS v3 9.8
EPSS 0.0118
EPSS Percentile 63.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-89
Status published
Products (1)
jflyfox/jfinal_cms 5.1.0
Published Sep 19, 2022
Tracked Since Feb 18, 2026