CVE-2020-23083: Malicious File Upload
Published May 3, 2021
·Updated
Unrestricted File Upload in JEECG v4.0 and earlier allows remote attackers to execute arbitrary code or gain privileges by uploading a crafted file to the component "jeecgFormDemoController.do?commonUpload".
Affected Software
1 affected component
Guojusoft Jeecg<=4.0
Event History
May 3, 2021
CVE Published
via MITRE·09:12 PM
Data Sourced
via MITRE·09:12 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2020-23083?
CVE-2020-23083 has a high severity rating due to the potential for arbitrary code execution and privilege escalation.
2
How do I fix CVE-2020-23083?
To fix CVE-2020-23083, upgrade to a version of JEECG later than 4.0 that addresses this vulnerability.
3
What types of attacks are possible due to CVE-2020-23083?
CVE-2020-23083 allows remote attackers to execute arbitrary code or escalate privileges through unrestricted file uploads.
4
Which versions of JEECG are affected by CVE-2020-23083?
JEECG versions 4.0 and earlier are affected by CVE-2020-23083.
5
Where does the vulnerability CVE-2020-23083 occur?
CVE-2020-23083 occurs in the "jeecgFormDemoController.do?commonUpload" component of the JEECG application.