CVE-2020-19229
CRITICALJeesite 1.2.7 - Code Injection
Title source: llmDescription
Jeesite 1.2.7 uses the apache shiro version 1.2.3 affected by CVE-2016-4437. Because of this version of the java deserialization vulnerability, an attacker could exploit the vulnerability to execute arbitrary commands via the rememberMe parameter.
Scores
CVSS v3
9.8
EPSS
0.0034
EPSS Percentile
56.7%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Classification
CWE
CWE-502
Status
published
Affected Products (1)
jeesite/jeesite
Timeline
Published
Apr 05, 2022
Tracked Since
Feb 18, 2026