References https://github.com/adysec/POC/blob/main/wpoc/JeecgBoot/JeecgBoot%E7%B3%BB%E7%BB%9FAviatorScript%E8%A1%A8%E8%BE%BE%E5%BC%8F%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md https://ilikeoyt.github.io/2024/08/13/jeecgboot-%E6%9D%83%E9%99%90%E7%BB%95%E8%BF%87-AviatorScript%E4%BB%A3%E7%A0%81%E6%89%A7%E8%A1%8C%E6%BC%8F%E6%B4%9E/ https://www.wangsu.com/news/content/blog/3742 https://blog.csdn.net/css33/article/details/150103269 https://whoopsunix.com/docs/java/Expression/Aviator/ https://zhuanlan.zhihu.com/p/1888282077968958078 https://fuping.site/2024/08/10/Jmreport-Auth-Bypass-Mitigation/ https://github.com/jeecgboot/jimureport/issues/2848 https://www.cnblogs.com/CVE-Lemon/collections/11743 https://www.cnblogs.com/CVE-Lemon/p/18392679 https://github.com/jeecgboot/jimureport/issues/2865 https://blog.csdn.net/weixin_33737134/article/details/159867414 https://y4tacker.github.io/2024/08/02/year/2024/8/%E6%9C%80%E6%96%B0%E7%89%88JeecgBoot%E7%AC%AC%E4%BA%8C%E5%BC%B9%E4%B9%8B%E5%8F%97%E9%99%90%E6%9D%A1%E4%BB%B6%E4%B8%8B%E7%9A%84%E5%86%85%E5%AD%98%E9%A9%AC%E6%B3%A8%E5%85%A5%E5%AE%9E%E5%BD%95/ https://github.com/jeecgboot/JeecgBoot/issues/7237 https://github.com/Threekiii/Vulnerability-Wiki/blob/master/docs-base/docs/webapp/JeecgBoot-SSTI-CVE-2023-4450.md https://github.com/jeecgboot/JeecgBoot/issues/4990 https://www.sxcast.edu.cn/uploadfile/ueditor/file/202510/1761869308d5a4ea.pdf
Related VulnerabilitiesJeecgBoot 积木报表 /jmreport/auto/export/python/plugin 代码执行漏洞JeecgBoot 权限绕过与SQL注入漏洞JeecgBoot 积木报表 /jmreport/getDataSourceByPage 信息泄露漏洞PoCJeecg JimuReport /jmreport/testConnection 代码执行漏洞(CVE-2025-66913)JeecgBoot积木报表getDataSourceByPage接口存在敏感信息泄露漏洞Jeecgboot /jmreport/save远程代码执行漏洞Jeecg-boot v2.1.2-v3.0.0 后台未授权SQL注入漏洞: Jeecg-boot v2.1.2-v3.0.0 后台未授权SQL注入漏洞jeecgboot-commoncontroller-parserxml-fileupload: Jeecgboot commonController parserXml fileuploadJeecg-Boot /sys/dict/queryTableData SQL 注入漏洞(CVE-2022-45205)Jeecg-Boot /sys/dict/loadTreeData SQL 注入漏洞(CVE-2023-38992)