Home/Product/jfinaloa project jfinaloa
Product

jfinaloa project jfinaloa

11 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2024-57776
< 2025.01.01
A cross-site scripting (XSS) vulnerability in the /apply/getEditPage?view interface of JFinalOA before v2025.01.01 allows attacker
4.6MEDIUM
CVE-2024-57775
< 2025-01-01
JFinalOA before v2025.01.01 was discovered to contain a SQL injection vulnerability via the component getWorkFlowHis?insid.
8.8HIGH
CVE-2024-57774
< 2025.01.01
A cross-site scripting (XSS) vulnerability in the getBusinessUploadListPage?busid interface of JFinalOA before v2025.01.01 allows
4.8MEDIUM
CVE-2024-57773
< 2025.01.01
A cross-site scripting (XSS) vulnerability in the openSelectManyUserPage?orgid interface of JFinalOA before v2025.01.01 allows att
4.8MEDIUM
CVE-2024-57772
< 2025.01.01
A cross-site scripting (XSS) vulnerability in the /bumph/getDraftListPage?type interface of JFinalOA before v2025.01.01 allows att
4.8MEDIUM
CVE-2024-57771
< 2025.01.01
A cross-site scripting (XSS) vulnerability in the common/getEditPage?view interface of JFinalOA before v2025.01.01 allows attacker
4.8MEDIUM
CVE-2024-57770
< 2025-01-01
JFinalOA before v2025.01.01 was discovered to contain a SQL injection vulnerability via the component apply/save#oaContractApply.i
8.8HIGH
CVE-2024-57769
< 2025-01-01
JFinalOA before v2025.01.01 was discovered to contain a SQL injection vulnerability via the component borrowmoney/listData?applyUs
8.8HIGH
CVE-2024-57768
< 2025-01-01
JFinalOA before v2025.01.01 was discovered to contain a SQL injection vulnerability via the component validRoleKey?sysRole.key.
9.8CRITICAL
CVE-2023-0758
all versions
A vulnerability was found in glorylion JFinalOA 1.0.2 and classified as critical. This issue affects some unknown processing of th
6.3MEDIUM
CVE-2021-40645
all versions
An SQL Injection vulnerability exists in glorylion JFinalOA as of 9/7/2021 in the defkey parameter getHaveDoneTaskDataList method
6.5MEDIUM
threatengine.sh