CVE-2023-47503
CVSS 3.1 Score 9.8 of 10 (high)
Details
Summary
CVE-2023-47503 is a newly identified vulnerability affecting the jflyfox jfinalCMS version 5.1.0. This issue enables a remote attacker to execute arbitrary code by crafting a malicious script that is processed by the login.jsp component in the template management module. An attacker can exploit this vulnerability to gain unauthorized access and potentially take control of affected systems. Successful exploitation could lead to serious consequences, including data theft or system compromise. It is recommended that users of jfinalCMS version 5.1.0 upgrade to a patched version as soon as possible to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.