References https://github.com/zhangdaiscott/jeecg-boot/issues/1888 https://zhuanlan.zhihu.com/p/1888282077968958078 https://github.com/admin772/POC/blob/main/JeecgBoot/Jeecg%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E4%B8%8A%E4%BC%A0%E6%BC%8F%E6%B4%9E.md https://cn-sec.com/archives/2703494.html https://github.com/MInggongK/jeecg- https://github.com/Msup5/JeecgGo https://github.com/zan8in/afrog/blob/3f4a033a359cad6385d3e33d01049349e49bcdbf/pocs/afrog-pocs/vulnerability/jeecgboot-commoncontroller-parserxml-fileupload.yaml
Related VulnerabilitiesJeecgBoot 积木报表 /jmreport/auto/export/python/plugin 代码执行漏洞JeecgBoot 权限绕过与SQL注入漏洞JeecgBoot 积木报表 /jmreport/getDataSourceByPage 信息泄露漏洞东胜物流软件 /Account/Chfee_payapplication/FileUpload 文件上传漏洞JeecgBoot积木报表getDataSourceByPage接口存在敏感信息泄露漏洞锐明技术Crocus系统 DeviceFileUpload.do 文件读取漏洞锐明技术 Crocus系统 DeviceFileUpload.do 任意文件读取漏洞锐捷EWEB路由器 /ddi/server/fileupload.php 文件上传漏洞锐明技术Crocus系统 DeviceFileUpload.do 任意文件读取漏洞MagicINFO SWUpdateFileUploader 文件上传漏洞