Description
Jeecg P3 Biz Chat 1.0.5 allows remote attackers to read arbitrary files through specific parameters.
Remediation
References
https://carl1l.github.io/2023/05/08/jeecg-p3-biz-chat-1-0-5-jar-has-arbitrary-file-read-vulnerability/
Related Vulnerabilities
CVE-2021-28169 Vulnerability in maven package org.eclipse.jetty:jetty-servlets
CVE-2023-48796 Vulnerability in maven package org.apache.dolphinscheduler:dolphinscheduler-api
CVE-2021-41411 Vulnerability in maven package org.drools:drools-core
CVE-2021-23372 Vulnerability in npm package mongo-express
CVE-2023-43494 Vulnerability in maven package org.jenkins-ci.main:jenkins-core