References https://www.wangsu.com/news/content/blog/3742 https://y4tacker.github.io/2024/08/01/year/2024/8/%E6%B5%85%E6%9E%90JeecgBoot-jmreport%E6%9C%80%E6%96%B0%E6%9D%83%E9%99%90%E7%BB%95%E8%BF%87/ https://github.com/jeecgboot/jimureport/issues/2865 https://fuping.site/2024/08/10/Jmreport-Auth-Bypass-Mitigation/ https://github.com/eeeeeeeeee-code/POC/blob/main/wpoc/JeecgBoot/jeecg-boot%E7%B3%BB%E7%BB%9F%E6%8E%A5%E5%8F%A3jmLink%E6%9D%83%E9%99%90%E7%BB%95%E8%BF%87%E6%BC%8F%E6%B4%9E.md https://www.secevery.com/toBugInfo?id=1819563301860974593 https://ilikeoyt.github.io/2024/08/13/jeecgboot-%E6%9D%83%E9%99%90%E7%BB%95%E8%BF%87-AviatorScript%E4%BB%A3%E7%A0%81%E6%89%A7%E8%A1%8C%E6%BC%8F%E6%B4%9E/ https://www.hnitns.com/index.php?id=281 https://zhuanlan.zhihu.com/p/1888282077968958078 https://www.cnblogs.com/tlnshuju/p/19314624
Related VulnerabilitiesJeecgBoot 积木报表 /jmreport/auto/export/python/plugin 代码执行漏洞JeecgBoot 权限绕过与SQL注入漏洞用友GRP-U8Cloud /jmreport/loadTableData SQL 注入漏洞用友 GRP-U8Cloud /jmreport/queryFieldBySql Freemarker 命令执行漏洞JeecgBoot 积木报表 /jmreport/getDataSourceByPage 信息泄露漏洞关于用友GRP-U8Cloud产品jmreport组件模块存漏洞的安全通告PoCJeecg JimuReport /jmreport/testConnection 代码执行漏洞(CVE-2025-66913)JeecgBoot积木报表getDataSourceByPage接口存在敏感信息泄露漏洞Jeecgboot /jmreport/save远程代码执行漏洞Jeecg-boot v2.1.2-v3.0.0 后台未授权SQL注入漏洞: Jeecg-boot v2.1.2-v3.0.0 后台未授权SQL注入漏洞jeecgboot-commoncontroller-parserxml-fileupload: Jeecgboot commonController parserXml fileuploadJeecg-Boot /sys/dict/queryTableData SQL 注入漏洞(CVE-2022-45205)