CVE-2023-49442

CRITICAL

Jeecg < 4.0 - Insecure Deserialization

Title source: rule

Description

Deserialization of Untrusted Data in jeecgFormDemoController in JEECG 4.0 and earlier allows attackers to run arbitrary code via crafted POST request.

Scores

CVSS v3 9.8
EPSS 0.5552
EPSS Percentile 98.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Classification

CWE
CWE-502
Status published

Affected Products (1)

jeecg/jeecg < 4.0

Timeline

Published Jan 03, 2024
Tracked Since Feb 18, 2026