anji-plus AJ-Report is affected by an authentication bypass vulnerability. A remote and unauthenticated attacker can append ;swagger-ui to HTTP requests to bypass authentication and execute arbitrary Java on the victim server.
The product requires authentication, but the product has an alternate path or channel that does not require authentication.
| Name | Vendor | Start Version | End Version | 
|---|---|---|---|
| Report | Anji-plus | * | 1.4.1 (excluding) |