anji-plus AJ-Report is affected by an authentication bypass vulnerability. A remote and unauthenticated attacker can append ;swagger-ui to HTTP requests to bypass authentication and execute arbitrary Java on the victim server. Exploitation evidence was observed by the Shadowserver Foundation on 2025-02-05 UTC.
The product requires authentication, but the product has an alternate path or channel that does not require authentication.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Report | Anji-plus | * | 1.4.1 (excluding) |