jeecgboot JimuReport是jeecgboot组织的一款报表应用组件。 jeecgboot JimuReport 2.3.4及之前版本存在授权问题漏洞,该漏洞源于报告文件夹模板列表端点存在认证绕过,可能导致未经身份验证的攻击者枚举所有报告并检索共享令牌,进而访问受保护的报告端点并获取完整的报告定义,包括嵌入的SQL语句和实时查询数据。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| jeecgboot | jimureport | ≤ 2.3.4 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| jeecgboot | jimureport | 0 ~ 2.3.4 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No comments yet