CVE-2025-66913
- EPSS 0.56%
- Veröffentlicht 08.01.2026 00:00:00
- Zuletzt bearbeitet 30.01.2026 01:06:25
JimuReport thru version 2.1.3 is vulnerable to remote code execution when processing user-controlled H2 JDBC URLs. The application passes the attacker-supplied JDBC URL directly to the H2 driver, allowing the use of certain directives to execute arbi...
CVE-2025-10771
- EPSS 0.07%
- Veröffentlicht 21.09.2025 23:02:07
- Zuletzt bearbeitet 08.10.2025 19:42:21
A vulnerability was determined in jeecgboot JimuReport up to 2.1.2. Affected is an unknown function of the file /drag/onlDragDataSource/testConnection of the component DB2 JDBC Handler. Executing manipulation of the argument clientRerouteServerListJN...
CVE-2025-10770
- EPSS 0.07%
- Veröffentlicht 21.09.2025 22:32:06
- Zuletzt bearbeitet 08.10.2025 19:52:02
A vulnerability was found in jeecgboot JimuReport up to 2.1.2. This impacts an unknown function of the file /drag/onlDragDataSource/testConnection of the component MySQL JDBC Handler. Performing manipulation results in deserialization. Remote exploit...
CVE-2025-8963
- EPSS 0.06%
- Veröffentlicht 14.08.2025 13:02:11
- Zuletzt bearbeitet 17.10.2025 17:55:36
A vulnerability was determined in jeecgboot JimuReport up to 2.1.1. Affected by this issue is some unknown functionality of the file /drag/onlDragDataSource/testConnection of the component Data Large Screen Template. The manipulation leads to deseria...
CVE-2024-44893
- EPSS 0.27%
- Veröffentlicht 10.09.2024 17:15:37
- Zuletzt bearbeitet 29.09.2025 13:52:01
An issue in the component /jeecg-boot/jmreport/dict/list of JimuReport v1.7.8 allows attacker to escalate privileges via a crafted GET request.
CVE-2023-6307
- EPSS 0.1%
- Veröffentlicht 27.11.2023 02:15:42
- Zuletzt bearbeitet 21.11.2024 08:43:35
A vulnerability classified as critical was found in jeecgboot JimuReport up to 1.6.1. Affected by this vulnerability is an unknown functionality of the file /download/image. The manipulation of the argument imageUrl leads to relative path traversal. ...
CVE-2023-4450
- EPSS 91.4%
- Veröffentlicht 21.08.2023 03:15:13
- Zuletzt bearbeitet 21.11.2024 08:35:11
A vulnerability was found in jeecgboot JimuReport up to 1.6.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the component Template Handler. The manipulation leads to injection. The attack can be laun...