JeeWMS before v2025.01.01 was discovered to contain a permission bypass in the component /interceptors/AuthInterceptor.cava.
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Link | Tags |
---|---|
https://gitee.com/erzhongxmu/JEEWMS/issues/IBFKBM | third party advisory issue tracking exploit |