Improper access control in Jfinal CMS 5.1.0 allows attackers to access sensitive information via /classes/conf/db.properties&config=filemanager.config.js.
The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.
Link | Tags |
---|---|
http://jfinalcms.com | broken link |
https://github.com/jflyfox/jfinal_cms | third party advisory product |
https://github.com/jflyfox/jfinal_cms/issues/27 | issue tracking exploit third party advisory |