First published: Mon Nov 27 2023(Updated: )
A vulnerability classified as critical was found in jeecgboot JimuReport up to 1.6.1. Affected by this vulnerability is an unknown functionality of the file /download/image. The manipulation of the argument imageUrl leads to relative path traversal. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-246133 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Credit: cna@vuldb.com
Affected Software | Affected Version | How to fix |
---|---|---|
<=1.6.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity level of CVE-2023-6307 is critical.
The affected software version of CVE-2023-6307 is Jeecg Jimureport up to 1.6.1.
CVE-2023-6307 is a critical vulnerability that allows remote attackers to perform path traversal through the imageUrl parameter in Jeecg Jimureport, leading to potential file manipulation.
Exploiting CVE-2023-6307 requires launching a remote attack by manipulating the imageUrl parameter in Jeecg Jimureport to perform relative path traversal.
To fix CVE-2023-6307, it is recommended to update Jeecg Jimureport to a version that contains the necessary security patches.