JeecgBoot是中国的一个适用于企业 Web 应用程序的 Java 低代码平台。 JeecgBoot JimuReport 1.6.0版本及之前版本存在注入漏洞。目前尚无此漏洞的相关信息,请随时关注CNNVD或厂商公告。
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
| 厂商 | 产品 | 影响版本 | CPE | 订阅 |
|---|---|---|---|---|
| jeecgboot | JimuReport | 1.0 | - |
|
| # | POC 描述 | 源链接 | 神龙链接 |
|---|---|---|---|
| 1 | None | https://github.com/ilikeoyt/CVE-2023-4450-Attack | POC详情 |
| 2 | A vulnerability was found in jeecgboot JimuReport up to 1.6.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the component Template Handler. The manipulation leads to injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2023/CVE-2023-4450.yaml | POC详情 |
| 3 | None | https://github.com/Threekiii/Awesome-POC/blob/master/Web%E5%BA%94%E7%94%A8%E6%BC%8F%E6%B4%9E/JimuReport%20FreeMarker%20%E6%9C%8D%E5%8A%A1%E7%AB%AF%E6%A8%A1%E6%9D%BF%E6%B3%A8%E5%85%A5%E5%91%BD%E4%BB%A4%E6%89%A7%E8%A1%8C%20CVE-2023-4450.md | POC详情 |
| 4 | None | https://github.com/Threekiii/Awesome-POC/blob/master/Web%E5%BA%94%E7%94%A8%E6%BC%8F%E6%B4%9E/JeecgBoot%20SSTI%20CVE-2023-4450.md | POC详情 |
| 5 | https://github.com/vulhub/vulhub/blob/master/jimureport/CVE-2023-4450/README.md | POC详情 |
未找到公开 POC。
登录以生成 AI POC暂无评论