Description
jjeecg-boot V3.5.0 has an unauthorized arbitrary file upload in /jeecg-boot/jmreport/upload interface.
Remediation
References
https://github.com/jeecgboot/jeecg-boot/issues/4990
Related Vulnerabilities
CVE-2021-21341 Vulnerability in maven package com.thoughtworks.xstream:xstream
CVE-2021-4307 Vulnerability in maven package org.webjars.npm:baobab
CVE-2018-14731 Vulnerability in npm package parcel-bundler
CVE-2022-1291 Vulnerability in npm package tableexport.jquery.plugin
CVE-2019-16869 Vulnerability in maven package io.netty:netty-codec-http