jjeecg-boot V3.5.0 has an unauthorized arbitrary file upload in /jeecg-boot/jmreport/upload interface.
References
Link | Resource |
---|---|
https://github.com/jeecgboot/jeecg-boot/issues/4990 | Exploit |
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2023-06-16 18:15
Updated : 2023-06-23 21:24
NVD link : CVE-2023-34660
Mitre link : CVE-2023-34660
CVE.ORG link : CVE-2023-34660
JSON object : View
Products Affected
jeecg
- jeecg_boot
CWE
CWE-434
Unrestricted Upload of File with Dangerous Type