A zip slip vulnerability in the component \service\migrate\MigrateForm.java of JEEWMS v3.7 allows attackers to execute arbitrary code via a crafted Zip file.
References
Link | Resource |
---|---|
https://github.com/wy876/cve/issues/7 | Exploit Issue Tracking |
Configurations
History
25 Apr 2025, 16:49
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:a:jeewms:jeewms:3.7:*:*:*:*:*:*:* | |
References | () https://github.com/wy876/cve/issues/7 - Exploit, Issue Tracking | |
First Time |
Jeewms
Jeewms jeewms |
16 Apr 2025, 19:15
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 5.5 |
CWE | CWE-22 |
16 Apr 2025, 13:25
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
15 Apr 2025, 19:16
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-04-15 19:16
Updated : 2025-04-25 16:49
NVD link : CVE-2025-29213
Mitre link : CVE-2025-29213
CVE.ORG link : CVE-2025-29213
JSON object : View
Products Affected
jeewms
- jeewms
CWE
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')