Aggregates CVE and security vulnerability intelligence across all jfinaloa_project-related products, including CVSS, EPSS, publication dates, and vulnerability intelligence data.
Historical issues mainly involve vendor risk sql injection and vendor risk cross-site scripting and related problems; some flaws may lead to vendor impact data exposure and vendor impact session compromise.
| CVE | Summary | Source | Max CVSS | EPSS % | Published | Updated |
|---|---|---|---|---|---|---|
| CVE-2024-57776 | A cross-site scripting (XSS) vulnerability in the /apply/getEditPage?view interface of JFinalOA before v2025.01.01 allows attackers to execute arbitrary web scripts or HTML via a crafted payload. | [email protected] | 4.6 | 0.25% | 2025-01-16 | 2025-05-17 |
| CVE-2024-57775 | JFinalOA before v2025.01.01 was discovered to contain a SQL injection vulnerability via the component getWorkFlowHis?insid. | [email protected] | 8.8 | 0.16% | 2025-01-16 | 2025-01-31 |
| CVE-2024-57774 | A cross-site scripting (XSS) vulnerability in the getBusinessUploadListPage?busid interface of JFinalOA before v2025.01.01 allows attackers to execute arbitrary web scripts or HTML via a crafted payload. | [email protected] | 4.8 | 0.18% | 2025-01-16 | 2025-05-17 |
| CVE-2024-57773 | A cross-site scripting (XSS) vulnerability in the openSelectManyUserPage?orgid interface of JFinalOA before v2025.01.01 allows attackers to execute arbitrary web scripts or HTML via a crafted payload. | [email protected] | 4.8 | 0.18% | 2025-01-16 | 2025-05-17 |
| CVE-2024-57772 | A cross-site scripting (XSS) vulnerability in the /bumph/getDraftListPage?type interface of JFinalOA before v2025.01.01 allows attackers to execute arbitrary web scripts or HTML via a crafted payload. | [email protected] | 4.8 | 0.18% | 2025-01-16 | 2025-05-17 |
| CVE-2024-57771 | A cross-site scripting (XSS) vulnerability in the common/getEditPage?view interface of JFinalOA before v2025.01.01 allows attackers to execute arbitrary web scripts or HTML via a crafted payload. | [email protected] | 4.8 | 0.19% | 2025-01-16 | 2025-05-17 |
| CVE-2024-57770 | JFinalOA before v2025.01.01 was discovered to contain a SQL injection vulnerability via the component apply/save#oaContractApply.id. | [email protected] | 8.8 | 0.16% | 2025-01-16 | 2025-01-23 |
| CVE-2024-57769 | JFinalOA before v2025.01.01 was discovered to contain a SQL injection vulnerability via the component borrowmoney/listData?applyUser. | [email protected] | 8.8 | 0.16% | 2025-01-16 | 2025-01-23 |
| CVE-2024-57768 | JFinalOA before v2025.01.01 was discovered to contain a SQL injection vulnerability via the component validRoleKey?sysRole.key. | [email protected] | 9.8 | 0.15% | 2025-01-16 | 2025-05-28 |
| CVE-2023-0758 | A vulnerability was found in glorylion JFinalOA 1.0.2 and classified as critical. This issue affects some unknown processing of the file src/main/java/com/pointlion/mvc/common/model/SysOrg.java. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-220469 was assigned to this vulnerability. | [email protected] | 6.3 | 0.34% | 2023-02-09 | 2024-11-21 |
| CVE-2021-40645 | An SQL Injection vulnerability exists in glorylion JFinalOA as of 9/7/2021 in the defkey parameter getHaveDoneTaskDataList method of the FlowTaskController. | [email protected] | 6.5 | 0.23% | 2022-03-30 | 2024-11-21 |