CVE-2019-17352
08.10.2019, 13:15
In JFinal cos before 2019-08-13, as used in JFinal 4.4, there is a vulnerability that can bypass the isSafeFile() function: one can upload any type of file. For example, a .jsp file may be stored and almost immediately deleted, but this deletion step does not occur for certain exceptions.Enginsight
Vendor | Product | Version |
---|---|---|
jfinal | jfinal | 𝑥 < 4.4 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References