Show filters
38 Total Results
Displaying 1-10 of 38
Sort by:
Attacker Value
Unknown

CVE-2023-49442

Disclosure Date: January 03, 2024 (last updated February 25, 2025)
Deserialization of Untrusted Data in jeecgFormDemoController in JEECG 4.0 and earlier allows attackers to run arbitrary code via crafted POST request.
Attacker Value
Unknown

CVE-2023-41544

Disclosure Date: December 30, 2023 (last updated February 25, 2025)
SSTI injection vulnerability in jeecg-boot version 3.5.3, allows remote attackers to execute arbitrary code via crafted HTTP request to the /jmreport/loadTableData component.
Attacker Value
Unknown

CVE-2023-41543

Disclosure Date: December 30, 2023 (last updated February 25, 2025)
SQL injection vulnerability in jeecg-boot v3.5.3, allows remote attackers to escalate privileges and obtain sensitive information via the component /sys/replicate/check.
Attacker Value
Unknown

CVE-2023-41542

Disclosure Date: December 30, 2023 (last updated February 25, 2025)
SQL injection vulnerability in jeecg-boot version 3.5.3, allows remote attackers to escalate privileges and obtain sensitive information via the jmreport/qurestSql component.
Attacker Value
Unknown

CVE-2023-6307

Disclosure Date: November 27, 2023 (last updated February 25, 2025)
A vulnerability classified as critical was found in jeecgboot JimuReport up to 1.6.1. Affected by this vulnerability is an unknown functionality of the file /download/image. The manipulation of the argument imageUrl leads to relative path traversal. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-246133 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Attacker Value
Unknown

CVE-2023-47467

Disclosure Date: November 22, 2023 (last updated February 25, 2025)
Directory Traversal vulnerability in jeecg-boot v.3.6.0 allows a remote privileged attacker to obtain sensitive information via the file directory structure.
Attacker Value
Unknown

CVE-2023-40989

Disclosure Date: September 22, 2023 (last updated February 25, 2025)
SQL injection vulnerbility in jeecgboot jeecg-boot v 3.0, 3.5.3 that allows a remote attacker to execute arbitrary code via a crafted request to the report/jeecgboot/jmreport/queryFieldBySql component.
Attacker Value
Unknown

CVE-2023-42268

Disclosure Date: September 08, 2023 (last updated February 25, 2025)
Jeecg boot up to v3.5.3 was discovered to contain a SQL injection vulnerability via the component /jeecg-boot/jmreport/show.
Attacker Value
Unknown

CVE-2023-41578

Disclosure Date: September 08, 2023 (last updated February 25, 2025)
Jeecg boot up to v3.5.3 was discovered to contain an arbitrary file read vulnerability via the interface /testConnection.
Attacker Value
Unknown

CVE-2023-4450

Disclosure Date: August 21, 2023 (last updated February 25, 2025)
A vulnerability was found in jeecgboot JimuReport up to 1.6.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the component Template Handler. The manipulation leads to injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 1.6.1 is able to address this issue. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-237571.