An arbitrary file upload vulnerability exists in JeeWMS 20250820, which is caused by the lack of file checking in the saveFiles function in /jeewms/cgUploadController.do. An attacker with normal privileges was able to upload a malicious file that would lead to remote code execution.
Metrics
Affected Vendors & Products
References
History
Fri, 10 Oct 2025 19:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-77 | |
Metrics |
cvssV3_1
|
Fri, 10 Oct 2025 18:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | An arbitrary file upload vulnerability exists in JeeWMS 20250820, which is caused by the lack of file checking in the saveFiles function in /jeewms/cgUploadController.do. An attacker with normal privileges was able to upload a malicious file that would lead to remote code execution. | |
References |
|

Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-10-10T18:55:13.791Z
Reserved: 2025-09-26T00:00:00.000Z
Link: CVE-2025-60268

Updated: 2025-10-10T18:55:05.806Z

Status : Received
Published: 2025-10-10T18:15:39.533
Modified: 2025-10-10T19:15:37.530
Link: CVE-2025-60268

No data.

No data.