jfinal_cms
jfinal_cms copied to clipboard
jfinal_ CMS 5.1.0 SQL injection
There is a SQLI vul in background mode.The route is as following

vulnerable argument passing is as following

I try to grab packets
Inject at orderby

Discovery injection
