CVE-2023-6307: jeecgboot JimuReport image path traversal
A vulnerability classified as critical was found in jeecgboot JimuReport up to 1.6.1. Affected by this vulnerability is an unknown functionality of the file /download/image. The manipulation of the argument imageUrl leads to relative path traversal. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-246133 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity level of CVE-2023-6307?
The severity level of CVE-2023-6307 is critical.
What is the affected software version of CVE-2023-6307?
The affected software version of CVE-2023-6307 is Jeecg Jimureport up to 1.6.1.
What is the vulnerability description of CVE-2023-6307?
CVE-2023-6307 is a critical vulnerability that allows remote attackers to perform path traversal through the imageUrl parameter in Jeecg Jimureport, leading to potential file manipulation.
How can I exploit CVE-2023-6307?
Exploiting CVE-2023-6307 requires launching a remote attack by manipulating the imageUrl parameter in Jeecg Jimureport to perform relative path traversal.
How do I fix CVE-2023-6307?
To fix CVE-2023-6307, it is recommended to update Jeecg Jimureport to a version that contains the necessary security patches.