Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Fix bug of "Cross-site Scripting in Jfinal CMS" #5

Open
hsluoyz opened this issue Sep 16, 2022 · 5 comments
Open

Fix bug of "Cross-site Scripting in Jfinal CMS" #5

hsluoyz opened this issue Sep 16, 2022 · 5 comments
Assignees
Labels
bug Something isn't working

Comments

@hsluoyz
Copy link
Member

hsluoyz commented Sep 16, 2022

https://github.com/jcasbin/jfinal-authz/security/dependabot/1

image

@PrathamJaiswal001
Copy link

@hsluoyz can you please elaborate it and also the link attached is not working.

@hsluoyz hsluoyz self-assigned this Dec 8, 2022
@hsluoyz hsluoyz added the bug Something isn't working label Dec 8, 2022
@hsluoyz
Copy link
Member Author

hsluoyz commented Dec 8, 2022

I think upgrading JFinal from v5.1.0 to a newer version would fix it

@hsluoyz
Copy link
Member Author

hsluoyz commented Dec 8, 2022

@OutOfEastGate

@OutOfEastGate
Copy link

@PrathamJaiswal001
The JFinal CMS is addressing this issue
details: jflyfox/jfinal_cms#47
A later upgrade to the latest version may fix it

@hsluoyz
Copy link
Member Author

hsluoyz commented Dec 10, 2022

@OutOfEastGate OK, let's wait for official fix

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bug Something isn't working
Projects
None yet
Development

No branches or pull requests

3 participants