Jeewms

Jeewms

20 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.04%
  • Veröffentlicht 31.05.2025 18:00:09
  • Zuletzt bearbeitet 11.09.2025 20:43:40

A vulnerability classified as critical was found in JeeWMS up to 20250504. Affected by this vulnerability is the function dogenerate of the file /generateController.do?dogenerate. The manipulation leads to sql injection. The attack can be launched re...

  • EPSS 0.06%
  • Veröffentlicht 31.05.2025 17:31:06
  • Zuletzt bearbeitet 11.09.2025 20:43:43

A vulnerability classified as critical has been found in JeeWMS up to 20250504. Affected is the function dogenerate of the file /generateController.do?dogenerate of the component File Handler. The manipulation leads to improper access controls. It is...

  • EPSS 0.18%
  • Veröffentlicht 31.05.2025 16:31:06
  • Zuletzt bearbeitet 11.09.2025 20:43:47

A vulnerability was found in JeeWMS up to 20250504. It has been declared as critical. This vulnerability affects the function doAdd of the file /cgformTemplateController.do?doAdd. The manipulation leads to path traversal. The attack can be initiated ...

  • EPSS 0.04%
  • Veröffentlicht 31.05.2025 16:00:09
  • Zuletzt bearbeitet 11.09.2025 20:43:49

A vulnerability was found in JeeWMS up to 20250504. It has been classified as critical. This affects the function CgAutoListController of the file /cgAutoListController.do?datagrid. The manipulation leads to sql injection. It is possible to initiate ...

Exploit
  • EPSS 0.34%
  • Veröffentlicht 15.04.2025 00:00:00
  • Zuletzt bearbeitet 25.04.2025 16:49:30

A zip slip vulnerability in the component \service\migrate\MigrateForm.java of JEEWMS v3.7 allows attackers to execute arbitrary code via a crafted Zip file.

Exploit
  • EPSS 0.22%
  • Veröffentlicht 15.01.2025 00:15:33
  • Zuletzt bearbeitet 11.09.2025 21:13:03

An arbitrary file upload vulnerability in the parserXML() method of JeeWMS before v2025.01.01 allows attackers to execute arbitrary code via uploading a crafted file.

Exploit
  • EPSS 0.18%
  • Veröffentlicht 15.01.2025 00:15:33
  • Zuletzt bearbeitet 21.04.2025 17:32:32

JeeWMS before v2025.01.01 was discovered to contain a SQL injection vulnerability via the ReportId parameter at /core/CGReportDao.java.

Exploit
  • EPSS 0.11%
  • Veröffentlicht 15.01.2025 00:15:33
  • Zuletzt bearbeitet 18.04.2025 19:18:47

JeeWMS before v2025.01.01 was discovered to contain a permission bypass in the component /interceptors/AuthInterceptor.cava.

Exploit
  • EPSS 0.26%
  • Veröffentlicht 05.03.2024 23:15:08
  • Zuletzt bearbeitet 21.01.2025 16:52:29

Directory Traversal vulnerability in Jeewms v.3.7 and before allows a remote attacker to obtain sensitive information via the cgformTemplateController component.

Exploit
  • EPSS 0.92%
  • Veröffentlicht 05.03.2024 23:15:07
  • Zuletzt bearbeitet 21.01.2025 18:32:16

An issue in Jeewms v.3.7 and before allows a remote attacker to escalate privileges via the AuthInterceptor component.