CVE-2026-2945: JeecgBoot uploadImgByHttp server-side request forgery
A weakness has been identified in JeecgBoot 3.9.0. Affected by this vulnerability is an unknown functionality of the file /sys/common/uploadImgByHttp. Executing a manipulation of the argument fileUrl can lead to server-side request forgery. The attack may be launched remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-2945?
CVE-2026-2945 is considered a high severity vulnerability due to its potential for server-side request forgery.
How do I fix CVE-2026-2945?
To fix CVE-2026-2945, it is recommended to update JeecgBoot to the latest version and implement input validation on the fileUrl parameter.
What is affected by CVE-2026-2945?
CVE-2026-2945 affects JeecgBoot version 3.9.0 and potentially earlier versions that include the vulnerable endpoint.
What type of vulnerability is CVE-2026-2945?
CVE-2026-2945 is classified as a server-side request forgery (SSRF) vulnerability.
Can CVE-2026-2945 be exploited remotely?
Yes, CVE-2026-2945 can be exploited remotely if the affected endpoint is accessible over the network.