VYPR

JEECG

by Jeecg

CVEs (7)

  • CVE-2023-49442CriJan 3, 2024
    risk 0.67cvss 9.8epss 0.39

    Deserialization of Untrusted Data in jeecgFormDemoController in JEECG 4.0 and earlier allows attackers to run arbitrary code via crafted POST request.

  • CVE-2020-23083CriMay 3, 2021
    risk 0.64cvss 9.8epss 0.04

    Unrestricted File Upload in JEECG v4.0 and earlier allows remote attackers to execute arbitrary code or gain privileges by uploading a crafted file to the component "jeecgFormDemoController.do?commonUpload".

  • CVE-2023-24789HigMar 6, 2023
    risk 0.57cvss 8.8epss 0.01

    jeecg-boot v3.4.4 was discovered to contain an authenticated SQL injection vulnerability via the building block report component.

  • CVE-2021-37306HigFeb 3, 2023
    risk 0.49cvss 7.5epss 0.01

    An Insecure Permissions issue in jeecg-boot 2.4.5 and earlier allows remote attackers to gain escalated privilege and view sensitive information via api uri: api uri:/sys/user/checkOnlyUser?username=admin.

  • CVE-2021-37305HigFeb 3, 2023
    risk 0.49cvss 7.5epss 0.04

    An Insecure Permissions issue in jeecg-boot 2.4.5 and earlier allows remote attackers to gain escalated privilege and view sensitive information via api uri: /sys/user/querySysUser?username=admin.

  • CVE-2021-37304HigFeb 3, 2023
    risk 0.49cvss 7.5epss 0.04

    An Insecure Permissions issue in jeecg-boot 2.4.5 allows unauthenticated remote attackers to gain escalated privilege and view sensitive information via the httptrace interface.

  • CVE-2020-20948HigDec 27, 2021
    risk 0.49cvss 7.5epss 0.01

    An arbitrary file download vulnerability in jeecg v3.8 allows attackers to access sensitive files via modification of the "localPath" variable.