CVE Vulnerabilities

CVE-2024-44893

Improper Privilege Management

Published: Sep 10, 2024 | Modified: Sep 29, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

An issue in the component /jeecg-boot/jmreport/dict/list of JimuReport v1.7.8 allows attacker to escalate privileges via a crafted GET request.

Weakness

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Affected Software

Name Vendor Start Version End Version
Jimureport Jeecg 1.7.8 (including) 1.7.8 (including)

Potential Mitigations

References