Command Injection Vulnerability in Jeecg Boot Software by Jeecg
CVE-2024-43028
9.8CRITICAL
What is CVE-2024-43028?
A command injection vulnerability exists in the component '/jmreport/show' of Jeecg Boot versions 3.0.0 through 3.5.3. This flaw enables attackers to craft a specific HTTP request, thereby executing arbitrary code on the affected system. Proper validation and sanitization of user inputs are crucial in preventing such security risks and protecting users from potential exploits.
