Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2025-45854 PoC — JEHC-BPM 安全漏洞

Source
Associated Vulnerability
Title:JEHC-BPM 安全漏洞 (CVE-2025-45854)
Description:JEHC-BPM是jehc个人开发者的一个BPM开源平台。 JEHC-BPM v2.0.1版本存在安全漏洞,该漏洞源于/server/executeExec组件存在任意文件上传,可能导致任意代码执行。
Description
A Remote Command Execution vulnerability in the component /server/executeExec of JEHC-BPM <= v2.0.1 allows attackers to execute arbitrary code. The vulnerability exists due to insufficient authorization checks in the executeExec endpoint which allows direct command execution.
File Snapshot

id: CVE-2025-45854 info: name: JEHC-BPM - Remote Code Execute author: ritikchaddha severity: ...
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. If the original source is unavailable, please email f.jinxu#gmail.com for a local snapshot (replace # with @).
    3. Shenlong has snapshotted the POC code for you. To support long-term maintenance, please consider donating. Thank you for your support.