Writeup Exploits
60,933 exploits tracked across all sources.
JeeWMS 771e4f5d0c01ffdeae1671be4cf102b73a3fe644 - Authentication Bypass and Arbitrary File Read
JeeWMS 771e4f5d0c01ffdeae1671be4cf102b73a3fe644 (2025-05-19) contains incorrect authentication bypass vulnerability, which can lead to arbitrary file reading.
CVSS 9.8
Guangzhou Huayi Intelligent Technology Jeewms < 2025-01-01 - SQL Injection via datagridGraph Function
A vulnerability, which was classified as critical, was found in Guangzhou Huayi Intelligent Technology Jeewms up to 20241229. Affected is the function datagridGraph of the file /graphReportController.do. The manipulation of the argument store_code leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 20250101 is able to address this issue. It is recommended to upgrade the affected component.
CVSS 6.3
Guangzhou Huayi Intelligent Technology Jeewms < 2025-01-01 - SQL Injection
A vulnerability, which was classified as critical, has been found in Guangzhou Huayi Intelligent Technology Jeewms up to 20241229. This issue affects the function saveOrUpdate of the file org/jeecgframework/web/cgform/controller/build/CgFormBuildController. java. The manipulation leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 20250101 is able to address this issue. It is recommended to upgrade the affected component.
CVSS 6.3
Guangzhou Huayi Intelligent Technology Jeewms < 2025-01-01 - Path Traversal via /wmOmNoticeHController.do
A vulnerability classified as critical was found in Guangzhou Huayi Intelligent Technology Jeewms up to 20241229. This vulnerability affects unknown code of the file /wmOmNoticeHController.do. The manipulation leads to path traversal: '../filedir'. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 20250101 is able to address this issue. It is recommended to upgrade the affected component.
CVSS 5.3
JeeWMS < 2025-01-01 - Arbitrary File Upload via parserXML() Method
An arbitrary file upload vulnerability in the parserXML() method of JeeWMS before v2025.01.01 allows attackers to execute arbitrary code via uploading a crafted file.
CVSS 8.1
jeewms < 2025.01.01 - SQL Injection via ReportId Parameter
JeeWMS before v2025.01.01 was discovered to contain a SQL injection vulnerability via the ReportId parameter at /core/CGReportDao.java.
CVSS 6.5
jeewms < 2025.01.01 - Missing Authorization in AuthInterceptor
JeeWMS before v2025.01.01 was discovered to contain a permission bypass in the component /interceptors/AuthInterceptor.cava.
CVSS 7.5
Jeewms v3.7 - SQL Injection via CgReportController API
Jeewms v3.7 was discovered to contain a SQL injection vulnerability via the CgReportController API.
CVSS 9.8
jeewms < 3.7 - Path Traversal via cgformTemplateController
Directory Traversal vulnerability in Jeewms v.3.7 and before allows a remote attacker to obtain sensitive information via the cgformTemplateController component.
CVSS 7.5
jeewms < 3.7 - Path Traversal via AuthInterceptor Component
An issue in Jeewms v.3.7 and before allows a remote attacker to escalate privileges via the AuthInterceptor component.
CVSS 9.8
Jeewms < 2024-11-08 - SQL Injection via cgReportController.do begin_date Parameter
A vulnerability was found in erzhongxmu Jeewms up to 20241108. It has been rated as critical. This issue affects some unknown processing of the file cgReportController.do of the component AuthInterceptor. The manipulation of the argument begin_date leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. This product does not use versioning. This is why information about affected and unaffected releases are unavailable. Other parameters might be affected as well.
CVSS 6.3
JEEWMS 1.0 - SQL Injection via id1 and id2 Parameters
JEEWMS 1.0 is vulnerable to SQL Injection. Attackers can inject malicious SQL statements through the id1 and id2 parameters in the /systemControl.do interface for attack.
CVSS 6.5
opencc JFlow <= 20260129 - XML External Entity Injection via File Argument in Imp_Done Function
A vulnerability was determined in opencc JFlow up to 20260129. This affects the function Imp_Done of the file src/main/java/bp/wf/httphandler/WF_Admin_AttrFlow.java of the component Workflow Engine. This manipulation of the argument File causes xml external entity reference. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through an issue report but has not responded yet.
CVSS 6.3
opencc JFlow <= 20260129 - XML External Entity Injection via File Argument in Imp_Done Function
A vulnerability was determined in opencc JFlow up to 20260129. This affects the function Imp_Done of the file src/main/java/bp/wf/httphandler/WF_Admin_AttrFlow.java of the component Workflow Engine. This manipulation of the argument File causes xml external entity reference. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through an issue report but has not responded yet.
CVSS 6.3
Anji-plus AJ-Report <1.4.2 - Auth Bypass
An authentication bypass vulnerability in anji-plus AJ-Report up to v1.4.2 allows unauthenticated attackers to execute arbitrary code via a crafted URL.
CVSS 9.8
SpringBootBlog v1.0.0 - Privilege Escalation
Incorrect access control in the preHandle function of SpringBootBlog v1.0.0 allows attackers to access sensitive components without authentication.
CVSS 7.5
my-site 1.0.2.RELEASE - Unauthenticated Improper Access Control in doFilter Function
Incorrect access control in the doFilter function of my-site v1.0.2.RELEASE allows attackers to access sensitive components without authentication.
CVSS 9.8
Jeewms v3.7 - SQL Injection via CgReportController API
Jeewms v3.7 was discovered to contain a SQL injection vulnerability via the CgReportController API.
CVSS 9.8
jsy-1 short-url 1.0.0 - Cross-Site Scripting via admin.php URL Parameter
A vulnerability classified as problematic has been found in jsy-1 short-url 1.0.0. Affected is an unknown function of the file admin.php. The manipulation of the argument url leads to cross site scripting. It is possible to launch the attack remotely. Upgrading to version 2.0.0 is able to address this issue. The name of the patch is 35c790897d6979392bc6f60707fc32da13a98b63. It is recommended to upgrade the affected component. The identifier of this vulnerability is VDB-266292.
CVSS 3.5
lakernote EasyAdmin <20240324 - XSS
A vulnerability classified as problematic has been found in lakernote EasyAdmin up to 20240324. This affects an unknown part of the file /sys/file/upload. The manipulation of the argument file leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. This product takes the approach of rolling releases to provide continious delivery. Therefore, version details for affected and updated releases are not available. The identifier of the patch is 9c8a836ace17a93c45e5ad52a2340788b7795030. It is recommended to apply a patch to fix this issue. The identifier VDB-266301 was assigned to this vulnerability.
CVSS 3.5
DedeCMS 5.7.114 - Remote Code Injection in article_template_rand.php
A vulnerability was found in DedeCMS 5.7.114. It has been classified as critical. This affects an unknown part of the file article_template_rand.php. The manipulation leads to code injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-271995. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
CVSS 4.7
ZZCMS 2023 - Path Traversal via /I/list.php Skin Parameter
A vulnerability was found in ZZCMS 2023. It has been declared as critical. This vulnerability affects unknown code of the file /I/list.php. The manipulation of the argument skin leads to path traversal. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
CVSS 5.3
ZZCMS 2023 - Information Disclosure via eginfo.php phome Parameter
A vulnerability was found in ZZCMS 2023. It has been rated as problematic. This issue affects some unknown processing of the file 3/E_bak5.1/upload/eginfo.php. The manipulation of the argument phome with the input ShowPHPInfo leads to information disclosure. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
CVSS 4.3
ZZCMS 2023 - Path Traversal via skin Parameter in about_edit.php
A vulnerability classified as critical has been found in ZZCMS 2023. Affected is an unknown function of the file /admin/about_edit.php?action=modify. The manipulation of the argument skin leads to path traversal. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
CVSS 7.3
ZZCMS 2023 - Path Traversal via skin[] Parameter in /admin/class.php
A vulnerability classified as critical was found in ZZCMS 2023. Affected by this vulnerability is an unknown functionality of the file /admin/class.php?dowhat=modifyclass. The manipulation of the argument skin[] leads to path traversal. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
CVSS 7.3
By Source