AJ-Report before version 1.4.1 is affected by an authentication bypass vulnerability. A remote and unauthenticated attacker can append ";swagger-ui" to HTTP requests to bypass authentication and execute arbitrary Java code on the victim server through script engine injection in the validation rules functionality.
id: CVE-2024-7314
info:
name: AJ-Report < 1.4.1 - Remote Code Execution
author: ritikchaddha
...