Junglewise Threat Intelligence

CVE-2023-49379: Cross-Site Request Forgery in JFinalCMS via the component /admin/friend_link/save

CVE-2023-49379 · Severity: low · CVSS 3.1 · Published 2023-12-05

Technologies: com.jfinal:jfinal (Maven). Vendors: Maven.

Executive brief

Cross-Site Request Forgery in JFinalCMS via the component /admin/friend_link/save

Affected products

  • Maven com.jfinal:jfinal

Related threats