CVE-2023-4450
MEDIUM EXPLOITED NUCLEIjeecg/jimureport < 1.6.1 - Server-Side Template Injection in Template Handler
Title source: llmExploitation Summary
CVE-2023-4450 has been observed exploited in the wild (reported by VulnCheck KEV). EIP tracks 1 public exploit from researchers including ilikeoyt. A Nuclei detection template is also available.
AI-analyzed exploit summary This repository contains a functional exploit for CVE-2023-4450 targeting JimuReport, featuring command execution and memory shell injection capabilities. The code includes multiple payloads (AntSwordShell, BehinderShell) and demonstrates weaponized exploitation techniques.
Description
A vulnerability was found in jeecgboot JimuReport up to 1.6.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the component Template Handler. The manipulation leads to injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 1.6.1 is able to address this issue. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-237571.
Exploits (1)
This repository contains a functional exploit for CVE-2023-4450 targeting JimuReport, featuring command execution and memory shell injection capabilities. The code includes multiple payloads (AntSwordShell, BehinderShell) and demonstrates weaponized exploitation techniques.
Nuclei Templates (1)
title:"Jeecg-Boot" || http.title:"jeecg-boot"
title="JeecgBoot 企业级低代码平台" || title="jeecg-boot" || title="jeecgboot 企业级低代码平台"
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L