Security Advisory

CVE-2020-19229

9.8
CRITICAL

Vulnerability Description

Jeesite 1.2.7 uses the apache shiro version 1.2.3 affected by CVE-2016-4437. Because of this version of the java deserialization vulnerability, an attacker could exploit the vulnerability to execute arbitrary commands via the rememberMe parameter.
Published Date April 5, 2022
Official Source NIST NVD Advisory