CVE-2020-19155: Jflyfox Jfinal CMS

High severity, CVSS 8.8. EPSS: 7.5% chance of exploitation in the next 30 days.

Improper Access Control in Jfinal CMS v4.7.1 and earlier allows remote attackers to obtain sensitive information and/or execute arbitrary code via the 'FileManager.rename()' function in the component 'modules/filemanager/FileManagerController.java'.

Affected products

  • Jflyfox Jfinal CMS: up to and including 4.7.1

Published 2021-09-15. Last modified 2026-06-17.