CVE-2023-4450
jeecgboot JimuReport Template injection
Record summary
CVE-2023-4450 has a selected CVSS score of 6.3 (medium); EIP currently links 1 Nuclei template.
Description
A vulnerability was found in jeecgboot JimuReport up to 1.6.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the component Template Handler. The manipulation leads to injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 1.6.1 is able to address this issue. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-237571.
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Aug 6, 2024 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Jul 2, 2025 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
jimureportBrowse jeecg / jimureport | VulnCheck | Version data not supplied | |
JimuReportBrowse jeecgboot / JimuReport | CVE List | 1.0 | affected |
| 1.1 | affected | ||
| 1.2 | affected | ||
| 1.3 | affected | ||
| 1.4 | affected | ||
| 1.5 | affected | ||
| 1.6 | affected | ||
Nuclei templates
1ProjectDiscoveryCRITICALJeecgBoot JimuReport - Template injection
A vulnerability was found in jeecgboot JimuReport up to 1.6.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the component Template Handler. The manipulation leads to injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
Impact
Unauthorized api called /jmreport/queryFieldBySql led to remote arbitrary code execution due to parsing SQL statements using Freemarker.
Remediation
Upgrading to version 1.6.1 is able to address this issue. It is recommended to upgrade the affected component.
Source: ProjectDiscovery