Home

Description

An arbitrary file upload vulnerability exists in JeeWMS 20250820, which is caused by the lack of file checking in the saveFiles function in /jeewms/cgUploadController.do. An attacker with normal privileges was able to upload a malicious file that would lead to remote code execution.

PUBLISHED Reserved 2025-09-26 | Published 2025-10-10 | Updated 2025-10-10 | Assigner mitre

References

gitee.com/erzhongxmu/JEEWMS

github.com/int-ux/report/issues/4

cve.org (CVE-2025-60268)

nvd.nist.gov (CVE-2025-60268)

Download JSON