CVE-2024-43028

A command injection vulnerability in the component /jmreport/show of jeecg boot v3.0.0 to v3.5.3 allows attackers to execute arbitrary code via a crafted HTTP request.
Configurations

Configuration 1 (hide)

cpe:2.3:a:jeecg:jeecg_boot:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-04-01 17:16

Updated : 2026-06-17 07:50


NVD link : CVE-2024-43028

Mitre link : CVE-2024-43028

CVE.ORG link : CVE-2024-43028


JSON object : View

Products Affected

jeecg

  • jeecg_boot
CWE
CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')