Vulnerabilities (CVE)

Filtered by vendor Jeewms Subscribe
Filtered by product Jeewms
Total 4 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-57760 1 Jeewms 1 Jeewms 2025-04-21 N/A 6.5 MEDIUM
JeeWMS before v2025.01.01 was discovered to contain a SQL injection vulnerability via the ReportId parameter at /core/CGReportDao.java.
CVE-2024-57757 1 Jeewms 1 Jeewms 2025-04-18 N/A 7.5 HIGH
JeeWMS before v2025.01.01 was discovered to contain a permission bypass in the component /interceptors/AuthInterceptor.cava.
CVE-2024-27764 1 Jeewms 1 Jeewms 2025-01-21 N/A 9.8 CRITICAL
An issue in Jeewms v.3.7 and before allows a remote attacker to escalate privileges via the AuthInterceptor component.
CVE-2024-27765 1 Jeewms 1 Jeewms 2025-01-21 N/A 7.5 HIGH
Directory Traversal vulnerability in Jeewms v.3.7 and before allows a remote attacker to obtain sensitive information via the cgformTemplateController component.