CVE-2024-40489

There is an injection vulnerability in jeecg boot versions 3.0.0 to 3.5.3 due to lax character filtering, which allows attackers to execute arbitrary code on components through specially crafted HTTP requests.
Configurations

Configuration 1 (hide)

cpe:2.3:a:jeecg:jeecg_boot:*:*:*:*:*:*:*:*

History

06 Apr 2026, 15:35

Type Values Removed Values Added
References () https://gist.github.com/aqyoung/2fd6329ceb06b731a621356921f0d5f0 - () https://gist.github.com/aqyoung/2fd6329ceb06b731a621356921f0d5f0 - Third Party Advisory
References () https://pan.baidu.com/s/14WOPXhRHoxr4FRKGme59ug?pwd=sktp - () https://pan.baidu.com/s/14WOPXhRHoxr4FRKGme59ug?pwd=sktp - Permissions Required
CPE cpe:2.3:a:jeecg:jeecg_boot:*:*:*:*:*:*:*:*
First Time Jeecg jeecg Boot
Jeecg

01 Apr 2026, 20:16

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
CWE CWE-94

01 Apr 2026, 17:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-01 17:16

Updated : 2026-04-06 15:35


NVD link : CVE-2024-40489

Mitre link : CVE-2024-40489

CVE.ORG link : CVE-2024-40489


JSON object : View

Products Affected

jeecg

  • jeecg_boot
CWE
CWE-94

Improper Control of Generation of Code ('Code Injection')