CVE-2025-5388
- EPSS 0.04%
- Veröffentlicht 31.05.2025 18:00:09
- Zuletzt bearbeitet 11.09.2025 20:43:40
A vulnerability classified as critical was found in JeeWMS up to 20250504. Affected by this vulnerability is the function dogenerate of the file /generateController.do?dogenerate. The manipulation leads to sql injection. The attack can be launched re...
CVE-2025-5387
- EPSS 0.06%
- Veröffentlicht 31.05.2025 17:31:06
- Zuletzt bearbeitet 11.09.2025 20:43:43
A vulnerability classified as critical has been found in JeeWMS up to 20250504. Affected is the function dogenerate of the file /generateController.do?dogenerate of the component File Handler. The manipulation leads to improper access controls. It is...
CVE-2025-5385
- EPSS 0.18%
- Veröffentlicht 31.05.2025 16:31:06
- Zuletzt bearbeitet 11.09.2025 20:43:47
A vulnerability was found in JeeWMS up to 20250504. It has been declared as critical. This vulnerability affects the function doAdd of the file /cgformTemplateController.do?doAdd. The manipulation leads to path traversal. The attack can be initiated ...
CVE-2025-5384
- EPSS 0.04%
- Veröffentlicht 31.05.2025 16:00:09
- Zuletzt bearbeitet 11.09.2025 20:43:49
A vulnerability was found in JeeWMS up to 20250504. It has been classified as critical. This affects the function CgAutoListController of the file /cgAutoListController.do?datagrid. The manipulation leads to sql injection. It is possible to initiate ...
CVE-2025-29213
- EPSS 0.34%
- Veröffentlicht 15.04.2025 00:00:00
- Zuletzt bearbeitet 25.04.2025 16:49:30
A zip slip vulnerability in the component \service\migrate\MigrateForm.java of JEEWMS v3.7 allows attackers to execute arbitrary code via a crafted Zip file.
CVE-2024-57761
- EPSS 0.22%
- Veröffentlicht 15.01.2025 00:15:33
- Zuletzt bearbeitet 11.09.2025 21:13:03
An arbitrary file upload vulnerability in the parserXML() method of JeeWMS before v2025.01.01 allows attackers to execute arbitrary code via uploading a crafted file.
CVE-2024-57760
- EPSS 0.18%
- Veröffentlicht 15.01.2025 00:15:33
- Zuletzt bearbeitet 21.04.2025 17:32:32
JeeWMS before v2025.01.01 was discovered to contain a SQL injection vulnerability via the ReportId parameter at /core/CGReportDao.java.
CVE-2024-57757
- EPSS 0.11%
- Veröffentlicht 15.01.2025 00:15:33
- Zuletzt bearbeitet 18.04.2025 19:18:47
JeeWMS before v2025.01.01 was discovered to contain a permission bypass in the component /interceptors/AuthInterceptor.cava.
CVE-2024-27765
- EPSS 0.26%
- Veröffentlicht 05.03.2024 23:15:08
- Zuletzt bearbeitet 21.01.2025 16:52:29
Directory Traversal vulnerability in Jeewms v.3.7 and before allows a remote attacker to obtain sensitive information via the cgformTemplateController component.
CVE-2024-27764
- EPSS 0.92%
- Veröffentlicht 05.03.2024 23:15:07
- Zuletzt bearbeitet 21.01.2025 18:32:16
An issue in Jeewms v.3.7 and before allows a remote attacker to escalate privileges via the AuthInterceptor component.