CVE-2020-28088: Malicious File Upload
An arbitrary file upload vulnerability in /jeecg-boot/sys/common/upload of jeecg-boot CMS 2.3 allows attackers to execute arbitrary code.
Other sources
An arbitrary file upload vulnerability in /jeecg-boot/sys/common/upload of jeecg-boot CMS 2.3 allows attackers to execute arbitrary code.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this arbitrary file upload vulnerability?
The vulnerability ID of this arbitrary file upload vulnerability is CVE-2020-28088.
What is the affected software version of this vulnerability?
The affected software version of this vulnerability is jeecg-boot CMS 2.3.
What is the severity of CVE-2020-28088?
The severity of CVE-2020-28088 is not specified in the provided information.
How can an attacker exploit this vulnerability?
An attacker can exploit this vulnerability by uploading arbitrary files to `/jeecg-boot/sys/common/upload`, allowing them to execute arbitrary code.
Is there a fix available for this vulnerability?
The provided information does not mention a specific fix for this vulnerability. Please refer to the provided references for any available patches or updates.