SSTI Injection Vulnerability in Jeecg-Boot Software by Jeecg
CVE-2023-41544
9.8CRITICAL
What is CVE-2023-41544?
A critical vulnerability has been identified in the Jeecg-Boot software version 3.5.3, which suffers from a Server Side Template Injection (SSTI) flaw. This vulnerability enables remote attackers to execute arbitrary code on the server through specially crafted HTTP requests targeted at the /jmreport/loadTableData component, potentially leading to unauthorized access and control over affected systems.
