In J2eeFAST <=2.7, the backend function has unsafe filtering, which allows an attacker to trigger certain sensitive functions resulting in arbitrary code execution.
Link | Tags |
---|---|
https://github.com/dromara/J2EEFAST | product |
https://gitee.com/dromara/J2EEFAST | product |
https://github.com/lazy-forever/CVE-Reference/tree/main/2024/45944 | third party advisory exploit |