Critical severity9.8NVD Advisory· Published Jan 3, 2024· Updated Jun 17, 2026
CVE-2023-49442
CVE-2023-49442
Description
Deserialization of Untrusted Data in jeecgFormDemoController in JEECG 4.0 and earlier allows attackers to run arbitrary code via crafted POST request.
Affected products
4- JEECG/JEECGdescription
- Range: <=4.0
Patches
Vulnerability mechanics
References
1- lemono.fun/thoughts/JEECG-RCE.htmlnvdBroken Link
News mentions
0No linked articles in our index yet.