CVE-2025-66913: Code Injection
JimuReport thru version 2.1.3 is vulnerable to remote code execution when processing user-controlled H2 JDBC URLs. The application passes the attacker-supplied JDBC URL directly to the H2 driver, allowing the use of certain directives to execute arbitrary Java code. A different vulnerability than CVE-2025-10770.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-66913?
CVE-2025-66913 is classified as a critical vulnerability due to its potential for remote code execution.
How do I fix CVE-2025-66913?
To fix CVE-2025-66913, upgrade JimuReport to version 2.1.4 or later, which addresses this vulnerability.
What kind of attack does CVE-2025-66913 allow?
CVE-2025-66913 allows attackers to exploit remote code execution via malicious user-controlled H2 JDBC URLs.
Which versions of JimuReport are affected by CVE-2025-66913?
JimuReport versions up to and including 2.1.3 are affected by CVE-2025-66913.
Can CVE-2025-66913 be exploited without user interaction?
Yes, CVE-2025-66913 can be exploited remotely, potentially without any user interaction.