Record summary

CVE-2023-4450 has a selected CVSS score of 6.3 (medium); EIP currently links 1 Nuclei template.

Description

A vulnerability was found in jeecgboot JimuReport up to 1.6.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the component Template Handler. The manipulation leads to injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 1.6.1 is able to address this issue. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-237571.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Aug 6, 2024 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationNone
AutomatableYes
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Jul 2, 2025 · Source: CVE List

Affected products and versions

2
ProductSourceVersion rangeStatus
VulnCheckVersion data not supplied
CVE List1.0affected
1.1affected
1.2affected
1.3affected
1.4affected
1.5affected
1.6affected

Nuclei templates

1
ProjectDiscoveryCRITICALJeecgBoot JimuReport - Template injection

A vulnerability was found in jeecgboot JimuReport up to 1.6.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the component Template Handler. The manipulation leads to injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

Impact

Unauthorized api called /jmreport/queryFieldBySql led to remote arbitrary code execution due to parsing SQL statements using Freemarker.

Remediation

Upgrading to version 1.6.1 is able to address this issue. It is recommended to upgrade the affected component.

AuthorsSumanth Vankineni
Template tagscvecve2023rcejeecgbootvkevvuln
Shodan: title:"Jeecg-Boot"
Shodan: http.title:"jeecg-boot"
FOFA: title="JeecgBoot 企业级低代码平台"
FOFA: title="jeecg-boot"
FOFA: title="jeecgboot 企业级低代码平台"
Google: intitle:"jeecg-boot"

Source: ProjectDiscovery

References

4