An arbitrary file upload vulnerability exists in JeeWMS 20250820, which is caused by the lack of file checking in the saveFiles function in /jeewms/cgUploadController.do. An attacker with normal privileges was able to upload a malicious file that would lead to remote code execution.
References
| Link | Resource |
|---|---|
| https://gitee.com/erzhongxmu/JEEWMS | Product |
| https://github.com/int-ux/report/issues/4 | Exploit Third Party Advisory Issue Tracking |
Configurations
History
No history.
Information
Published : 2025-10-10 18:15
Updated : 2025-10-16 15:39
NVD link : CVE-2025-60268
Mitre link : CVE-2025-60268
CVE.ORG link : CVE-2025-60268
JSON object : View
Products Affected
huayi-tec
- jeewms
CWE
CWE-77
Improper Neutralization of Special Elements used in a Command ('Command Injection')
