cvemon logocvemon logo

Activity

Trending

CVE-2025-45854

Published Jun 3, 2025

Last updated a month ago

CVSS critical 10.0
  1. Overview

  2. Scores

  3. Weaknesses

  4. Social media

  5. References

Overview

Description
/server/executeExec of JEHC-BPM 2.0.1 allows attackers to execute arbitrary code via execParams.
Source
cve@mitre.org
NVD status
Awaiting Analysis

Risk scores

CVSS 3.1

Type
Secondary
Base score
10
Impact score
6
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Severity
CRITICAL

Weaknesses

cve@mitre.org
CWE-862
134c704f-9b21-4f2e-91b3-4a467353bcc0
CWE-434

Social media

Hype score
Not currently trending
  1. 🚨 CVE-2025-45854 - critical 🚨 JEHC-BPM - Remote Code Execute > A Remote Command Execution vulnerability in the component /server/executeExec of JEHC... 👾 https://t.co/xAZtivvffJ @pdnuclei #NucleiTemplates #cve

    @pdnuclei_bot

    22 Jun 2025

    197 Impressions

    1 Retweet

    2 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. CVE-2025-45854 An arbitrary file upload vulnerability in the component /server/executeExec of JEHC-BPM v2.0.1 allows attackers to execute arbitrary code via uploading a crafted file. https://t.co/A1SL0Pmvid

    @CVEnew

    3 Jun 2025

    335 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

References

Sources include official advisories and independent security research.

  • https://nvd.nist.gov/vuln/detail/CVE-2025-45854
  • https://gist.github.com/Cafe-Tea/bc14b38f4bfd951de2979a24c3358460
  • https://gitee.com/jehc/JEHC-BPM
  • https://web.archive.org/web/20250604134020/https://gist.github.com/Cafe-Tea/bc14b38f4bfd951de2979a24c3358460/revisions
TRY INTRUDER
Intruder logo

© 2025 Intruder Systems Ltd.

AboutPrivacySitemapFeeds