CVE-2023-49442
CRITICALJeecg < 4.0 - Insecure Deserialization
Title source: ruleDescription
Deserialization of Untrusted Data in jeecgFormDemoController in JEECG 4.0 and earlier allows attackers to run arbitrary code via crafted POST request.
References (1)
Scores
CVSS v3
9.8
EPSS
0.5552
EPSS Percentile
98.0%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Classification
CWE
CWE-502
Status
published
Affected Products (1)
jeecg/jeecg
< 4.0
Timeline
Published
Jan 03, 2024
Tracked Since
Feb 18, 2026