JEECG
by Jeecg
CVEs (7)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-49442 | Cri | 0.67 | 9.8 | 0.39 | Jan 3, 2024 | Deserialization of Untrusted Data in jeecgFormDemoController in JEECG 4.0 and earlier allows attackers to run arbitrary code via crafted POST request. | ||
| CVE-2020-23083 | Cri | 0.64 | 9.8 | 0.04 | May 3, 2021 | Unrestricted File Upload in JEECG v4.0 and earlier allows remote attackers to execute arbitrary code or gain privileges by uploading a crafted file to the component "jeecgFormDemoController.do?commonUpload". | ||
| CVE-2023-24789 | Hig | 0.57 | 8.8 | 0.01 | Mar 6, 2023 | jeecg-boot v3.4.4 was discovered to contain an authenticated SQL injection vulnerability via the building block report component. | ||
| CVE-2021-37306 | Hig | 0.49 | 7.5 | 0.01 | Feb 3, 2023 | An Insecure Permissions issue in jeecg-boot 2.4.5 and earlier allows remote attackers to gain escalated privilege and view sensitive information via api uri: api uri:/sys/user/checkOnlyUser?username=admin. | ||
| CVE-2021-37305 | Hig | 0.49 | 7.5 | 0.04 | Feb 3, 2023 | An Insecure Permissions issue in jeecg-boot 2.4.5 and earlier allows remote attackers to gain escalated privilege and view sensitive information via api uri: /sys/user/querySysUser?username=admin. | ||
| CVE-2021-37304 | Hig | 0.49 | 7.5 | 0.04 | Feb 3, 2023 | An Insecure Permissions issue in jeecg-boot 2.4.5 allows unauthenticated remote attackers to gain escalated privilege and view sensitive information via the httptrace interface. | ||
| CVE-2020-20948 | Hig | 0.49 | 7.5 | 0.01 | Dec 27, 2021 | An arbitrary file download vulnerability in jeecg v3.8 allows attackers to access sensitive files via modification of the "localPath" variable. |
- risk 0.67cvss 9.8epss 0.39
Deserialization of Untrusted Data in jeecgFormDemoController in JEECG 4.0 and earlier allows attackers to run arbitrary code via crafted POST request.
- risk 0.64cvss 9.8epss 0.04
Unrestricted File Upload in JEECG v4.0 and earlier allows remote attackers to execute arbitrary code or gain privileges by uploading a crafted file to the component "jeecgFormDemoController.do?commonUpload".
- risk 0.57cvss 8.8epss 0.01
jeecg-boot v3.4.4 was discovered to contain an authenticated SQL injection vulnerability via the building block report component.
- risk 0.49cvss 7.5epss 0.01
An Insecure Permissions issue in jeecg-boot 2.4.5 and earlier allows remote attackers to gain escalated privilege and view sensitive information via api uri: api uri:/sys/user/checkOnlyUser?username=admin.
- risk 0.49cvss 7.5epss 0.04
An Insecure Permissions issue in jeecg-boot 2.4.5 and earlier allows remote attackers to gain escalated privilege and view sensitive information via api uri: /sys/user/querySysUser?username=admin.
- risk 0.49cvss 7.5epss 0.04
An Insecure Permissions issue in jeecg-boot 2.4.5 allows unauthenticated remote attackers to gain escalated privilege and view sensitive information via the httptrace interface.
- risk 0.49cvss 7.5epss 0.01
An arbitrary file download vulnerability in jeecg v3.8 allows attackers to access sensitive files via modification of the "localPath" variable.