Description
jjeecg-boot V3.5.0 has an unauthorized arbitrary file upload in /jeecg-boot/jmreport/upload interface.
Remediation
References
https://github.com/jeecgboot/jeecg-boot/issues/4990
Related Vulnerabilities
CVE-2022-39312 Vulnerability in maven package io.dataease:dataease-plugin-common
CVE-2016-0709 Vulnerability in maven package org.apache.portals.jetspeed-2:j2-admin
CVE-2020-23622 Vulnerability in maven package org.fourthline.cling:cling-core
CVE-2020-7746 Vulnerability in npm package chart.js
CVE-2020-22755 Vulnerability in maven package net.mingsoft:ms-mcms