Critical severity9.8NVD Advisory· Published Dec 30, 2023· Updated Jun 17, 2026
CVE-2023-41544
CVE-2023-41544
Description
SSTI injection vulnerability in jeecg-boot version 3.5.3, allows remote attackers to execute arbitrary code via crafted HTTP request to the /jmreport/loadTableData component.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.jeecgframework.boot:jeecg-boot-commonMaven | <= 3.5.3 | — |
Affected products
3- jeecg-boot/jeecg-bootdescription
Patches
Vulnerability mechanics
References
4- pho3n1x-web.github.io/2023/09/18/CVE-2023-41544%28JeecgBoot_SSTI%29/nvdExploitThird Party Advisory
- github.com/advisories/GHSA-49jp-cghc-p5pjghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2023-41544ghsaADVISORY
- pho3n1x-web.github.io/2023/09/18/CVE-2023-41544%28JeecgBoot_SSTI%29ghsaWEB
News mentions
0No linked articles in our index yet.