CVE-2019-17352

CVE-2019-17352

In JFinal cos before 2019-08-13, as used in JFinal 4.4, there is a vulnerability that can bypass the isSafeFile() function: one can upload any type of file. For example, a .jsp file may be stored and almost immediately deleted, but this deletion step does not occur for certain exceptions.

Source: CVE-2019-17352

답글 남기기

이메일 주소는 공개되지 않습니다. 필수 필드는 *로 표시됩니다