-
CVSS Score
-The XSS occurs because:
While exact code isn't available, JFinal's architecture suggests the vulnerability exists in the core request handling mechanism that binds parameters to template rendering contexts without adequate escaping, particularly for form field values like the password parameter in the admin login flow.
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| com.jfinal:jfinal | maven | <= 5.0.0 |
A Semantic Attack on Google Gemini - Read the Latest Research