VendorsHuayi-tecjeewms2025-08-20
Vulnerabilities

Huayi-tec Jeewms 2025-08-20

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

2CVEs
CVE-2025-60269
JEEWMS 20250820 is vulnerable to SQL Injection in the exportXls function located in the src/main/java/org/jeecgframework/web/cgreport/controller/excel/CgExportExcelController.java file.
Published 2025-10-10 · Analyzed
9.4EPSS 0.003
CVE-2025-60268
An arbitrary file upload vulnerability exists in JeeWMS 20250820, which is caused by the lack of file checking in the saveFiles function in /jeewms/cgUploadController.do. An attacker with normal privileges was able to upload a malicious file that would lead to remote code execution.
Published 2025-10-10 · Analyzed
6.5EPSS 0.004