Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2021-37305 PoC — jeecg 安全漏洞

Source
Associated Vulnerability
Title:jeecg 安全漏洞 (CVE-2021-37305)
Description:jeecg是一个应用软件。一款基于代码生成器的智能开发平台。 jeecg-boot 2.4.5版本存在安全漏洞,该漏洞源于权限设置不安全。攻击者利用该漏洞通过uri:/sys/user/querySysUser?username=admin获得升级的权限并查看敏感信息。
Description
Jeecg Boot <= 2.4.5 API interface has unauthorized access and leaks sensitive information such as email,phone and Enumerate usernames that exist in the system.
File Snapshot

id: CVE-2021-37305 info: name: Jeecg Boot <= 2.4.5 - Sensitive Information Disclosure author: r ...
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. If the original source is unavailable, please email f.jinxu#gmail.com for a local snapshot (replace # with @).
    3. Shenlong has snapshotted the POC code for you. To support long-term maintenance, please consider donating. Thank you for your support.