Server-Side Template Injection (SSTI) vulnerability in jFinal v.4.9.08 allows a remote attacker to execute arbitrary code via the template function.
| Software | From | Fixed in |
|---|---|---|
com.jfinal / jfinal
|
- | 4.9.08.x |
| jfinal / jfinal | 4.9.08 | 4.9.08.x |