{"id":"CVE-2021-40639","title":"Improper access control in Jfinal CMS 5.1.0 allows attackers to access sensitive information via /classes/conf/db.properties&config=filemanager.config.js.","summary":"Improper access control in Jfinal CMS 5.1.0 allows attackers to access sensitive information via /classes/conf/db.properties&config=filemanager.config.js.","severity":"high","cvss":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","cwe":["CWE-668","CWE-863"],"vendor":"jflyfox","product":"jfinal_cms","affected":["jfinal_cms = 5.1.0"],"published":"2021-09-15","updated":"2026-07-05","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2021-40639","references":[{"url":"https://github.com/jflyfox/jfinal_cms","label":"cve@mitre.org"},{"url":"https://github.com/jflyfox/jfinal_cms/issues/27","label":"cve@mitre.org"},{"url":"http://jfinalcms.com","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://github.com/jflyfox/jfinal_cms","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://github.com/jflyfox/jfinal_cms/issues/27","label":"af854a3a-2127-422b-91ae-364da2661108"}],"tags":["nvd"],"epss":0.01198,"epssPercentile":0.66777,"ingestedAt":"2026-07-06T17:03:23.571Z","slug":"CVE-2021-40639","body":"## Overview\n\nImproper access control in Jfinal CMS 5.1.0 allows attackers to access sensitive information via /classes/conf/db.properties&config=filemanager.config.js.\n\n## Affected\n\n- `jfinal_cms = 5.1.0`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":41,"depthScoreParts":{"impact":41.3,"likelihood":0.2,"exploitation":0,"ransomware":0},"changes":[]}