ZeroHour

CVE-2023-38991

PoC
CVSS 3.1
5.4 medium
EPSS
<1%p39
Published
()
Modified
Description

An issue in the delete function in the ActModelController class of jeesite v1.2.6 allows authenticated attackers to arbitrarily delete models created by the Administrator.

Vendors
jeesite
Products
jeesite
Weakness
CWE-732
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L

In the news

No ingested article mentions this CVE yet.