jeecg Vulnerabilities and Affected Products
Vulnerabilities associated with jimureport.
Products
Clear product- jeecg-boot2 vulnerabilities
- jimureport2 vulnerabilities
- jeecg1 vulnerability
- JeecgBoot1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2024-44893CRITICAL | An issue in the component /jeecg-boot/jmreport/dict/list of JimuReport v1.7.8 allows attacker to escalate privileges via a crafted GET request. CWE-269Sep 10, 2024 | CVSS9.8v3.1 | EPSS0.528% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-4450MEDIUM | jeecgboot JimuReport Template injectionA vulnerability was found in jeecgboot JimuReport up to 1.6.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the component Template Handler. The manipulation leads to injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 1.6.1 is able to address this issue. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-237571. | CVSS6.3v3.1 | EPSS11.4% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei template | STIX |