Arbitrary File Upload Vulnerability in JeeWMS by erzhongxmu
CVE-2025-60268
6.5MEDIUM
What is CVE-2025-60268?
An arbitrary file upload vulnerability exists in JeeWMS version 20250820 due to insufficient file validation in the saveFiles function located in /jeewms/cgUploadController.do. This weakness allows an attacker with standard permissions to upload a malicious file, potentially leading to remote code execution, which can compromise system integrity and security.
