Export CSV

Products

1 vendor
VendorProductsCVEsKEVAvg EPSSWorst Severity
111029.6%CRITICAL

Related CVEs

11
CVE IDDescriptionSeverityCVSSKEVEPSSPublished
CVE-2024-57776A cross-site scripting (XSS) vulnerability in the /apply/getEditPage?view interface of JFinalOA before v2025.01.01 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.MEDIUM4.619.0%Jan 16, 2025
CVE-2024-57775JFinalOA before v2025.01.01 was discovered to contain a SQL injection vulnerability via the component getWorkFlowHis?insid.HIGH8.842.8%Jan 16, 2025
CVE-2024-57774A cross-site scripting (XSS) vulnerability in the getBusinessUploadListPage?busid interface of JFinalOA before v2025.01.01 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.MEDIUM4.819.6%Jan 16, 2025
CVE-2024-57773A cross-site scripting (XSS) vulnerability in the openSelectManyUserPage?orgid interface of JFinalOA before v2025.01.01 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.MEDIUM4.819.6%Jan 16, 2025
CVE-2024-57772A cross-site scripting (XSS) vulnerability in the /bumph/getDraftListPage?type interface of JFinalOA before v2025.01.01 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.MEDIUM4.819.6%Jan 16, 2025
CVE-2024-57771A cross-site scripting (XSS) vulnerability in the common/getEditPage?view interface of JFinalOA before v2025.01.01 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.MEDIUM4.822.4%Jan 16, 2025
CVE-2024-57770JFinalOA before v2025.01.01 was discovered to contain a SQL injection vulnerability via the component apply/save#oaContractApply.id.HIGH8.842.8%Jan 16, 2025
CVE-2024-57769JFinalOA before v2025.01.01 was discovered to contain a SQL injection vulnerability via the component borrowmoney/listData?applyUser.HIGH8.842.8%Jan 16, 2025
CVE-2024-57768JFinalOA before v2025.01.01 was discovered to contain a SQL injection vulnerability via the component validRoleKey?sysRole.key.CRITICAL9.837.7%Jan 16, 2025
CVE-2023-0758A vulnerability was found in glorylion JFinalOA 1.0.2 and classified as critical. This issue affects some unknown processing of the file src/main/java/com/pointlion/mvc/common/model/SysOrg.java. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-220469 was assigned to this vulnerability.CRITICAL9.8Feb 9, 2023
CVE-2021-40645An SQL Injection vulnerability exists in glorylion JFinalOA as of 9/7/2021 in the defkey parameter getHaveDoneTaskDataList method of the FlowTaskController.MEDIUM6.5Mar 30, 2022