Critical severity9.8NVD Advisory· Published Apr 1, 2026· Updated Apr 6, 2026
CVE-2024-43028
CVE-2024-43028
Description
A command injection vulnerability in the component /jmreport/show of jeecg boot v3.0.0 to v3.5.3 allows attackers to execute arbitrary code via a crafted HTTP request.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- gist.github.com/aqyoung/e3b7ba5d8b8261df7d09931dbe779b3bnvdThird Party Advisory
- pan.baidu.com/s/1h2RGEvxuvsKtsn2-TlFlmAnvdPermissions Required
News mentions
0No linked articles in our index yet.