← volver
CVE-2023-4450mediumexplotación observadaCWE-74

jeecgboot JimuReport Template injection

75Vexday Risk Score

Corrige ahora. Ella explotación observada por VulnCheck y tiene exploit funcional público.

ssvc Actcvss 6.3epss 11%
de la publicación al arma170 días
Publicada en NVD21 ago
1ª PoC+170d
VulnCheck+351d
probabilidad de explotación
11%top 4% de las CVE
explotación observada
VulnCheck
1 exploit(s) público(s)
A vulnerability was found in jeecgboot JimuReport up to 1.6.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the component Template Handler. The manipulation leads to injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 1.6.1 is able to address this issue. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-237571.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Productos afectados
jeecgboot · JimuReport
⚠ Recursos públicos, para evaluar la exposición de sistemas que controlas o estás autorizado a probar. Prueba solo con autorización.