CVE-2020-19229

CRITICAL

Jeesite 1.2.7 - Code Injection

Title source: llm

Description

Jeesite 1.2.7 uses the apache shiro version 1.2.3 affected by CVE-2016-4437. Because of this version of the java deserialization vulnerability, an attacker could exploit the vulnerability to execute arbitrary commands via the rememberMe parameter.

Scores

CVSS v3 9.8
EPSS 0.0034
EPSS Percentile 56.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Classification

CWE
CWE-502
Status published

Affected Products (1)

jeesite/jeesite

Timeline

Published Apr 05, 2022
Tracked Since Feb 18, 2026