jeecgboot JimuReport Template injection
75Vexday Risk Score
Patch now. It exploitation observed by VulnCheck and has a working public exploit.
ssvc Actcvss 6.3epss 11%
from disclosure to weapon170 days
Published on NVDAug 21
1st PoC+170d
VulnCheck+351d
exploitation probability
11%top 4% of all CVEs
observed exploitation
yesVulnCheck
1 public exploit(s)
A vulnerability was found in jeecgboot JimuReport up to 1.6.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the component Template Handler. The manipulation leads to injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 1.6.1 is able to address this issue. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-237571.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Affected products
jeecgboot · JimuReportpublic PoCs found — 1
vulncheckvulncheck.com/xdb/ee5af2a9df25unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.