


Perceptive Security
SOC/SIEM Consultancy

A command injection vulnerability in the component /jmreport/show of jeecg boot v3.0.0 to v3.5.3 allows attackers to execute arbitrary code via a crafted HTTP r…
Published:
31 March 2026 at 22:00:00
Alert date:
1 April 2026 at 21:03:40
Source:
nvd.nist.gov
Web Technologies, Enterprise Applications
A command injection vulnerability has been identified in the /jmreport/show component of JeecgBoot framework versions 3.0.0 through 3.5.3. The vulnerability allows attackers to execute arbitrary code on affected systems through specially crafted HTTP requests. This represents a critical security flaw that could lead to complete system compromise. The affected versions span multiple releases of the popular Java-based development framework. Proof-of-concept exploits and technical details are publicly available, increasing the risk of active exploitation.
Technical details
Mitigation steps:
Affected products:
JeecgBoot
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2024-43028
https://gist.github.com/aqyoung/e3b7ba5d8b8261df7d09931dbe779b3b
https://pan.baidu.com/s/1h2RGEvxuvsKtsn2-TlFlmA?pwd=gf5r
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
