Description
jjeecg-boot V3.5.0 has an unauthorized arbitrary file upload in /jeecg-boot/jmreport/upload interface.
Remediation
References
https://github.com/jeecgboot/jeecg-boot/issues/4990
Related Vulnerabilities
CVE-2011-1772 Vulnerability in maven package com.opensymphony:xwork-core
CVE-2021-23358 Vulnerability in maven package org.webjars.bowergithub.jashkenas:underscore
CVE-2022-45685 Vulnerability in maven package org.codehaus.jettison:jettison
CVE-2016-10735 Vulnerability in npm package bootstrap
CVE-2018-16487 Vulnerability in maven package org.webjars.npm:lodash.mergewith