jflyfox/jfinal_cms

Arbitrary file reading vulnerability exists

hacker-mao opened this issue · 1 comments

Enter the background, edit /template/includes/jquery.html in the template management , poc is as follows

${printFile('../../../../../../../../../../../../../../../etc/passwd')}

image

Reopen the homepage http://localhost:8877/jfinal_cms/ , can see /etc/passwd

image