ZeroHour

CVE-2024-40489

CVSS 3.1
9.8 critical
EPSS
<1%p42
Published
()
Modified
Description

There is an injection vulnerability in jeecg boot versions 3.0.0 to 3.5.3 due to lax character filtering, which allows attackers to execute arbitrary code on components through specially crafted HTTP requests.

Vendors
jeecg
Products
jeecg boot
Weakness
CWE-94
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.