CVE-2023-4450

MEDIUM EXPLOITED NUCLEI

jeecg/jimureport < 1.6.1 - Server-Side Template Injection in Template Handler

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2023-4450 has been observed exploited in the wild (reported by VulnCheck KEV). EIP tracks 1 public exploit from researchers including ilikeoyt. A Nuclei detection template is also available.

AI-analyzed exploit summary This repository contains a functional exploit for CVE-2023-4450 targeting JimuReport, featuring command execution and memory shell injection capabilities. The code includes multiple payloads (AntSwordShell, BehinderShell) and demonstrates weaponized exploitation techniques.

Description

A vulnerability was found in jeecgboot JimuReport up to 1.6.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the component Template Handler. The manipulation leads to injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 1.6.1 is able to address this issue. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-237571.

Exploits (1)

nomisec WORKING POC 22 stars
by ilikeoyt · remote
https://github.com/ilikeoyt/CVE-2023-4450-Attack

This repository contains a functional exploit for CVE-2023-4450 targeting JimuReport, featuring command execution and memory shell injection capabilities. The code includes multiple payloads (AntSwordShell, BehinderShell) and demonstrates weaponized exploitation techniques.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: JimuReport
No auth needed
Prerequisites: Access to vulnerable JimuReport instance · Java runtime environment
devstral-2 · analyzed Feb 19, 2026 Full analysis →

Nuclei Templates (1)

JeecgBoot JimuReport - Template injection
CRITICALVERIFIEDby Sumanth Vankineni
Shodan: title:"Jeecg-Boot" || http.title:"jeecg-boot"
FOFA: title="JeecgBoot 企业级低代码平台" || title="jeecg-boot" || title="jeecgboot 企业级低代码平台"

References (3)

Core 3
Core References
VDB Entry vdb-entry technical-description
https://vuldb.com/?id.237571
Permissions Required, VDB Entry signature permissions-required
https://vuldb.com/?ctiid.237571
Broken Link broken-link exploit issue-tracking
https://github.com/keecth/bug/blob/main/jimureport%20ssti(RCE).md

Scores

CVSS v3 6.3
EPSS 0.1141
EPSS Percentile 95.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

VulnCheck KEV 2024-08-06
CWE
CWE-74
Status published
Products (1)
jeecg/jimureport < 1.6.1
Published Aug 21, 2023
Tracked Since Feb 18, 2026