References https://github.com/jeecgboot/JeecgBoot/issues/7014 https://www.cnblogs.com/CVE-Lemon/p/18392679 https://fuping.site/2024/08/10/Jmreport-Auth-Bypass-Mitigation/ https://ilikeoyt.github.io/2024/08/13/jeecgboot-%E6%9D%83%E9%99%90%E7%BB%95%E8%BF%87-AviatorScript%E4%BB%A3%E7%A0%81%E6%89%A7%E8%A1%8C%E6%BC%8F%E6%B4%9E/ https://cn-sec.com/archives/3245442.html https://github.com/adysec/POC/blob/main/wpoc/JeecgBoot/JeecgBoot%E7%B3%BB%E7%BB%9FAviatorScript%E8%A1%A8%E8%BE%BE%E5%BC%8F%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md https://github.com/jeecgboot/JimuReport/issues/2848 https://blog.csdn.net/css33/article/details/150103269 https://whoopsunix.com/docs/java/Expression/Aviator/ https://zhuanlan.zhihu.com/p/1888282077968958078
Related VulnerabilitiesJeecgBoot 积木报表 /jmreport/auto/export/python/plugin 代码执行漏洞JeecgBoot 权限绕过与SQL注入漏洞JeecgBoot 积木报表 /jmreport/getDataSourceByPage 信息泄露漏洞JeecgBoot积木报表getDataSourceByPage接口存在敏感信息泄露漏洞jeecgboot-commoncontroller-parserxml-fileupload: Jeecgboot commonController parserXml fileuploadPoCCVE-2023-34659: JeecgBoot 3.5.0 - SQL InjectionPoCCVE-2023-4450: JeecgBoot JimuReport - Template injectionPoCCVE-2024-48307: JeecgBoot v3.7.1 - SQL InjectionPoCjeecg-boot-passwordChange-unauth: JeecgBoot Password Reset VulnerabilityPoCjeecgboot-passwordchange-user-reset-unauth: JeecgBoot 任意用户密码重置PoCjeecgboot-swagger: JeecgBoot 后台服务 API 接口文档JeecgBoot /onlDragDatasetHead/getTotalData SQL注入漏洞(CVE-2024-48307)