There is an injection vulnerability in jeecg boot versions 3.0.0 to 3.5.3 due to lax character filtering, which allows attackers to execute arbitrary code on components through specially crafted HTTP requests.
References
| Link | Resource |
|---|---|
| https://gist.github.com/aqyoung/2fd6329ceb06b731a621356921f0d5f0 | Third Party Advisory |
| https://pan.baidu.com/s/14WOPXhRHoxr4FRKGme59ug?pwd=sktp | Permissions Required |
Configurations
History
No history.
Information
Published : 2026-04-01 17:16
Updated : 2026-06-17 07:45
NVD link : CVE-2024-40489
Mitre link : CVE-2024-40489
CVE.ORG link : CVE-2024-40489
JSON object : View
Products Affected
jeecg
- jeecg_boot
CWE
CWE-94
Improper Control of Generation of Code ('Code Injection')
