Описание
JeecgBoot server-side template injection
SSTI injection vulnerability in jeecg-boot version 3.5.3, allows remote attackers to execute arbitrary code via crafted HTTP request to the /jmreport/loadTableData component.
Пакеты
Наименование
org.jeecgframework.boot:jeecg-boot-common
maven
Затронутые версииВерсия исправления
<= 3.5.3
Отсутствует
Связанные уязвимости
CVSS3: 9.8
nvd
около 2 лет назад
SSTI injection vulnerability in jeecg-boot version 3.5.3, allows remote attackers to execute arbitrary code via crafted HTTP request to the /jmreport/loadTableData component.