CVE-2020-19150: Jflyfox Jfinal CMS

High severity, CVSS 8.1. EPSS: 3.5% chance of exploitation in the next 30 days.

Improper Access Control in Jfinal CMS v4.7.1 and earlier allows remote attackers to obtain sensitive information or cause a denial of service via the 'FileManager.delete()' function in the component 'modules/filemanager/FileManagerController.java'.

Affected products

  • Jflyfox Jfinal CMS: up to and including 4.7.1

Published 2021-09-15. Last modified 2026-06-17.