github.comexploit
https://github.com/hadagaga/vuln/blob/master/JFinalCMS/Server_Side%20_Template_Injection/Server-Side-Template-Injection.md CVE-2024-12350
MEDIUM
JFinalCMS Template TemplateController.java update command injection
Record summary
CVE-2024-12350 has a selected CVSS score of 5.3 (medium).
Description
A vulnerability was found in JFinalCMS 1.0. It has been rated as critical. Affected by this issue is the function update of the file \src\main\java\com\cms\controller\admin\TemplateController.java of the component Template Handler. The manipulation of the argument content leads to command injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationPoC
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Dec 9, 2024 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
jfinalcmsBrowse jfinalcms_project / jfinalcmsDefault status: unknown | CVE List | 1.0 | affected |
JFinalCMS | CVE List | 1.0 | affected |
References
5nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2024-12350 VDB-287270 | CTI Indicators (IOB, IOC, TTP, IOA)signaturepermissions required
https://vuldb.com/?ctiid.287270 VDB-287270 | JFinalCMS Template TemplateController.java update command injectionvdb entryTechnical description
https://vuldb.com/?id.287270 Submit #456047 | jwillber JFinalCMS TemplateController.java content 1 Command InjectionThird-party advisory
https://vuldb.com/?submit.456047