Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Lem0N817

#19057of 53,633
14Total CVSS
Vulnerabilities · 2
Medium
1
High
1
PT-2025-20655
7.5
2025-05-11
Unknown · Jeecg-Boot · CVE-2025-4533
**Name of the Vulnerable Software and Affected Versions** JeecgBoot versions up to 3.8.0 **Description** A vulnerability was found in JeecgBoot that affects the function `unzipFile` of the file `/jeecg-boot/airag/knowledge/doc/import/zip` of the component Document Library Upload. The manipulation of the argument `File` leads to resource consumption. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. **Recommendations** For JeecgBoot versions up to 3.8.0, consider disabling the `unzipFile` function until a patch is available to prevent remote resource consumption. Restrict access to the `/jeecg-boot/airag/knowledge/doc/import/zip` file to minimize the risk of exploitation. Avoid using the `File` argument in the affected component until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
PT-2024-28340
6.5
2024-07-16
Seacms · Seacms · CVE-2024-39036
**Name of the Vulnerable Software and Affected Versions** SeaCMS version 12.9 **Description** The issue concerns an Arbitrary File Read vulnerability. It is exploited via the `admin safe.php` file. **Recommendations** For SeaCMS version 12.9, consider restricting access to the `admin safe.php` file until a patch is available.