CVE-2025-60268
An arbitrary file upload vulnerability exists in JeeWMS 20250820, which is caused by the lack of file checking in the sa
An arbitrary file upload vulnerability exists in JeeWMS 20250820, which is caused by the lack of file checking in the saveFiles function in /jeewms/cgUploadController.do. An attacker with normal privileges was able to upload a malicious file that would lead to remote code execution.
MEDIUM · CVSS 6.5
EPSS 0.00176
Schedule remediation
- Public exploit or PoC is available
Sigma rules0
YARA rules0