CVE-2023-41544: Code Injection
Published Dec 30, 2023
·Updated
SSTI injection vulnerability in jeecg-boot version 3.5.3, allows remote attackers to execute arbitrary code via crafted HTTP request to the /jmreport/loadTableData component.
Affected Software
2 affected components
maven/org.jeecgframework.boot:jeecg-boot-common<=3.5.3
Jeecg jeecg boot<=3.5.3
Event History
Dec 30, 2023
CVE Published
12:00 AM
Data Sourced
12:00 AM
Description
Advisory Published
06:30 AM
Frequently Asked Questions
1
What is the severity of CVE-2023-41544?
CVE-2023-41544 is categorized as a critical severity vulnerability due to the potential for remote code execution.
2
How do I fix CVE-2023-41544?
To fix CVE-2023-41544, upgrade to a version of jeecg-boot that is higher than 3.5.3.
3
What are the implications of CVE-2023-41544?
The implications of CVE-2023-41544 include the risk of unauthorized access and manipulation of sensitive data via arbitrary code execution.
4
Which versions of jeecg-boot are affected by CVE-2023-41544?
Versions of jeecg-boot up to and including 3.5.3 are affected by CVE-2023-41544.
5
What type of vulnerability is CVE-2023-41544?
CVE-2023-41544 is a Server-Side Template Injection (SSTI) vulnerability.