VYPR

J2eeFAST

by Dromara

CVEs (3)

  • CVE-2024-45944CriOct 18, 2024
    risk 0.64cvss 9.8epss 0.01

    In J2eeFAST <=2.7, the backend function has unsafe filtering, which allows an attacker to trigger certain sensitive functions resulting in arbitrary code execution.

  • CVE-2023-2476LowMay 2, 2023
    risk 0.23cvss 3.5epss 0.01

    A vulnerability was found in Dromara J2eeFAST up to 2.6.0. It has been classified as problematic. Affected is an unknown function of the component Announcement Handler. The manipulation of the argument 系统工具/公告管理 leads to cross site scripting. It is possible to…

  • CVE-2023-2475LowMay 2, 2023
    risk 0.23cvss 3.5epss 0.01

    A vulnerability was found in Dromara J2eeFAST up to 2.6.0 and classified as problematic. This issue affects some unknown processing of the component System Message Handler. The manipulation of the argument 主题 leads to cross site scripting. The attack may be initiated…