CVE-2024-7314
02.08.2024, 17:16
anji-plus AJ-Report is affected by an authentication bypass vulnerability. A remote and unauthenticated attacker can append ";swagger-ui" to HTTP requests to bypass authentication and execute arbitrary Java on the victim server.Exploitation evidence was observed by the Shadowserver Foundation on 2025-02-05 UTC.Enginsight
| Vendor | Product | Version |
|---|---|---|
| anji-plus | report | 𝑥 < 1.4.1 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration