CVE-2025-5387

A vulnerability classified as critical has been found in JeeWMS up to 20250504. Affected is the function dogenerate of the file /generateController.do?dogenerate of the component File Handler. The manipulation leads to improper access controls. It is possible to launch the attack remotely. This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available.
References
Link Resource
https://gitee.com/erzhongxmu/JEEWMS/issues/IC5FNV Issue Tracking
https://vuldb.com/?ctiid.310680 Permissions Required VDB Entry
https://vuldb.com/?id.310680 Third Party Advisory VDB Entry
Configurations

Configuration 1 (hide)

cpe:2.3:a:huayi-tec:jeewms:*:*:*:*:*:*:*:*

History

11 Sep 2025, 20:43

Type Values Removed Values Added
References () https://gitee.com/erzhongxmu/JEEWMS/issues/IC5FNV - () https://gitee.com/erzhongxmu/JEEWMS/issues/IC5FNV - Issue Tracking
References () https://vuldb.com/?ctiid.310680 - () https://vuldb.com/?ctiid.310680 - Permissions Required, VDB Entry
References () https://vuldb.com/?id.310680 - () https://vuldb.com/?id.310680 - Third Party Advisory, VDB Entry
CPE cpe:2.3:a:huayi-tec:jeewms:*:*:*:*:*:*:*:*
First Time Huayi-tec
Huayi-tec jeewms
CWE NVD-CWE-noinfo

02 Jun 2025, 17:32

Type Values Removed Values Added
New CVE

Information

Published : 2025-05-31 18:15

Updated : 2025-09-11 20:43


NVD link : CVE-2025-5387

Mitre link : CVE-2025-5387

CVE.ORG link : CVE-2025-5387


JSON object : View

Products Affected

huayi-tec

  • jeewms
CWE
CWE-266

Incorrect Privilege Assignment

CWE-284

Improper Access Control

NVD-CWE-noinfo