An arbitrary file upload vulnerability exists in JeeWMS 20250820, which is caused by the lack of file checking in the saveFiles function in /jeewms/cgUploadController.do. An attacker with normal privileges was able to upload a malicious file that would lead to remote code execution.
Metrics
Affected Vendors & Products
References
History
Mon, 20 Oct 2025 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Jeewms
Jeewms jeewms |
|
| Vendors & Products |
Jeewms
Jeewms jeewms |
Thu, 16 Oct 2025 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Huayi-tec
Huayi-tec jeewms |
|
| CPEs | cpe:2.3:a:huayi-tec:jeewms:2025-08-20:*:*:*:*:*:*:* | |
| Vendors & Products |
Huayi-tec
Huayi-tec jeewms |
Fri, 10 Oct 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-77 | |
| Metrics |
cvssV3_1
|
Fri, 10 Oct 2025 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An arbitrary file upload vulnerability exists in JeeWMS 20250820, which is caused by the lack of file checking in the saveFiles function in /jeewms/cgUploadController.do. An attacker with normal privileges was able to upload a malicious file that would lead to remote code execution. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published: 2025-10-10T00:00:00.000Z
Updated: 2025-10-10T18:55:13.791Z
Reserved: 2025-09-26T00:00:00.000Z
Link: CVE-2025-60268
Updated: 2025-10-10T18:55:05.806Z
Status : Analyzed
Published: 2025-10-10T18:15:39.533
Modified: 2025-10-16T15:39:43.447
Link: CVE-2025-60268
No data.