Author: Angelo Barbosa

CVE-2024-57771 | JFinalOA 1.0.2 common/getEditPage?view cross site scripting

A vulnerability was found in JFinalOA 1.0.2. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file common/getEditPage?view. The manipulation leads to cross site scripting. This vulnerability is known as CVE-2024-57771. The attack can be launched remotely. There is no exploit available. It is recommended to upgrade the affected...

Read More

CVE-2025-0518 | FFmpeg 7.1 av_cold return value

A vulnerability was found in FFmpeg 7.1 and classified as problematic. Affected by this issue is the function av_cold. The manipulation leads to unchecked return value. This vulnerability is handled as CVE-2025-0518. Access to the local network is required for this attack. There is no exploit available. It is recommended to apply a patch to fix this...

Read More

CVE-2024-57159 | 07FLY FlyCMS 1.3.9 add.html cross-site request forgery

A vulnerability, which was classified as problematic, has been found in 07FLY FlyCMS 1.3.9. This issue affects some unknown processing of the file /oa/OaWorkReport/add.html. The manipulation leads to cross-site request forgery. The identification of this vulnerability is CVE-2024-57159. The attack may be initiated remotely. Furthermore, there is an exploit...

Read More