Showing 2 vulnerabilities on this page for jimureport

Signals CISA KEV Ransomware Nuclei
jeecg vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

An issue in the component /jeecg-boot/jmreport/dict/list of JimuReport v1.7.8 allows attacker to escalate privileges via a crafted GET request.

CWE-269Sep 10, 2024
CVSS9.8v3.1EPSS0.528%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

jeecgboot JimuReport Template injection

A vulnerability was found in jeecgboot JimuReport up to 1.6.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the component Template Handler. The manipulation leads to injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 1.6.1 is able to address this issue. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-237571.

CWE-74Aug 21, 20231 related artifact
CVSS6.3v3.1EPSS11.4%PoCs0SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX