Review reviewHigh
CVE-2021-40639
jfinal cms
Improper access control in Jfinal CMS 5.1.0 allows attackers to access sensitive information via /classes/conf/db.properties&config=filemanager.config.js.
- CVSS
- 7.5
- EPSS
- 1.19% 64.9% percentile
- CISA KEV
- Not listed
- Published
- 2021.09.16