CyberRota Analysis
AI-GeneratedJimuReport is vulnerable due to an authentication bypass in the report folder template listing endpoint, enabling unauthenticated attackers to enumerate reports and obtain share tokens. This exposure allows attackers to access protected report endpoints, potentially retrieving sensitive information such as SQL statements and live query data. Organizations using JimuReport should prioritize addressing this vulnerability to mitigate the risk of unauthorized data access.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
JimuReport contains an authentication bypass vulnerability in the report folder template listing endpoint that allows unauthenticated attackers to enumerate all reports and retrieve share tokens. Attackers can use disclosed share tokens to access protected report endpoints and retrieve full report definitions including embedded SQL statements and live query data.