A vulnerability, which was classified as critical, has been found in JeeWMS up to 20250504. Affected by this issue is the function dogenerateOne2Many of the file /generateController.do?dogenerateOne2Many of the component File Handler. The manipulation leads to improper access controls. The attack may be launched remotely. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available.
Advisories
Source ID Title
EUVD EUVD EUVD-2025-16570 A vulnerability, which was classified as critical, has been found in JeeWMS up to 20250504. Affected by this issue is the function dogenerateOne2Many of the file /generateController.do?dogenerateOne2Many of the component File Handler. The manipulation leads to improper access controls. The attack may be launched remotely. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Fri, 12 Sep 2025 05:45:00 +0900

Type Values Removed Values Added
First Time appeared Huayi-tec
Huayi-tec jeewms
Weaknesses NVD-CWE-noinfo
CPEs cpe:2.3:a:huayi-tec:jeewms:*:*:*:*:*:*:*:*
Vendors & Products Huayi-tec
Huayi-tec jeewms

Tue, 03 Jun 2025 05:15:00 +0900

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 01 Jun 2025 03:45:00 +0900

Type Values Removed Values Added
Description A vulnerability, which was classified as critical, has been found in JeeWMS up to 20250504. Affected by this issue is the function dogenerateOne2Many of the file /generateController.do?dogenerateOne2Many of the component File Handler. The manipulation leads to improper access controls. The attack may be launched remotely. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available.
Title JeeWMS File generateController.do dogenerateOne2Many access control
Weaknesses CWE-266
CWE-284
References
Metrics cvssV2_0

{'score': 6.5, 'vector': 'AV:N/AC:L/Au:S/C:P/I:P/A:P'}

cvssV3_0

{'score': 6.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L'}

cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2025-06-02T15:46:55.361Z

Reserved: 2025-05-30T12:46:42.499Z

Link: CVE-2025-5389

cve-icon Vulnrichment

Updated: 2025-06-02T15:15:52.759Z

cve-icon NVD

Status : Analyzed

Published: 2025-05-31T19:15:20.730

Modified: 2025-09-11T20:43:38.010

Link: CVE-2025-5389

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-06-24T18:44:15Z