← Back to browse
·
API
CVE-2025-45854
Severity
CRITICAL
CVSS
10.0
EPSS
0.02794
Risk score
40.98
CISA KEV
No
PoC
No
Published
2025-06-03
Modified
2025-08-26
First seen
2026-08-07
Aliases
EUVD-2025-16756, GHSA-G3C7-95HC-GV66
Products
JEHc:JEHC-BPM 2.0.1, n/a:n/a n/a
Sources
euvd
EUVD-2025-16756
Description
/server/executeExec of JEHC-BPM 2.0.1 allows attackers to execute arbitrary code via execParams.
References
https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-16756
https://gitee.com/jehc/JEHC-BPM
https://gist.github.com/Cafe-Tea/bc14b38f4bfd951de2979a24c3358460
https://web.archive.org/web/20250604134020/https://gist.github.com/Cafe-Tea/bc14b38f4bfd951de2979a24c3358460/revisions