PT-2026-39413 · Unknown · Jeecg-Boot
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
JeecgBoot versions prior to 3.9.2
Description
A cross-site scripting issue exists in the SVG File Handler component within the file
jeecg-module-system/jeecg-system-biz/src/main/java/org/jeecg/modules/system/controller/CommonController.java. This flaw allows a remote attacker to execute malicious scripts via manipulation of an unknown function in the specified controller.Recommendations
Update to a version later than 3.9.1.
As a temporary workaround, restrict access to the SVG File Handler component in
CommonController.java to minimize the risk of exploitation.Exploit
Fix
XSS
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Jeecg-Boot