CVE-2023-4450

MEDIUM EXPLOITED NUCLEI

Jeecg Jimureport < 1.6.1 - Injection

Title source: rule

Description

A vulnerability was found in jeecgboot JimuReport up to 1.6.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the component Template Handler. The manipulation leads to injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 1.6.1 is able to address this issue. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-237571.

Exploits (1)

nomisec WORKING POC 22 stars
by ilikeoyt · remote
https://github.com/ilikeoyt/CVE-2023-4450-Attack

Nuclei Templates (1)

JeecgBoot JimuReport - Template injection
CRITICALVERIFIEDby Sumanth Vankineni
Shodan: title:"Jeecg-Boot" || http.title:"jeecg-boot"
FOFA: title="JeecgBoot 企业级低代码平台" || title="jeecg-boot" || title="jeecgboot 企业级低代码平台"

Scores

CVSS v3 6.3
EPSS 0.9117
EPSS Percentile 99.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

Details

VulnCheck KEV 2024-08-06
CWE
CWE-74
Status published
Products (1)
jeecg/jimureport < 1.6.1
Published Aug 21, 2023
Tracked Since Feb 18, 2026