{
  "affected": [
    {
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "last_affected": "4e9757217f58aa3373c29a2c4035a1dbe2cc4d79"
            }
          ],
          "repo": "https://github.com/jflyfox/jfinal_cms",
          "type": "GIT"
        }
      ]
    }
  ],
  "details": "JFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/friend_link/update.",
  "id": "CVE-2023-49375",
  "modified": "2025-11-19T17:35:19.808518044Z",
  "published": "2023-12-05T15:15:07.913Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://github.com/cui2shark/cms/blob/main/There%20is%20CSRF%20in%20the%20modification%20of%20the%20friendship%20link.md"
    },
    {
      "type": "EVIDENCE",
      "url": "https://github.com/cui2shark/cms/blob/main/There%20is%20CSRF%20in%20the%20modification%20of%20the%20friendship%20link.md"
    }
  ],
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "type": "CVSS_V3"
    }
  ]
}