PT-2024-38260 · Anji Plus · Anji-Plus Aj-Report

CVE-2024-7314

·

Published

2024-08-02

·

Updated

2025-11-20

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions anji-plus AJ-Report versions <= 1.4.0
Description The issue allows a remote and unauthenticated attacker to bypass authentication by appending ";swagger-ui" to HTTP requests, potentially executing arbitrary Java on the victim server. This is due to improper handling of insufficient permissions via the /swagger-ui endpoint.
Recommendations For anji-plus AJ-Report versions <= 1.4.0, upgrade immediately to mitigate the risk of remote exploit. As a temporary workaround, consider restricting access to the /swagger-ui endpoint to minimize the risk of exploitation.

Exploit

Fix

RCE

Authentication Bypass Using an Alternate Path or Channel

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-7314

Affected Products

Anji-Plus Aj-Report