CVE-2024-7314: Anji-Plus Report

Critical severity, CVSS 9.8. EPSS: 51.8% chance of exploitation in the next 30 days.

anji-plus AJ-Report is affected by an authentication bypass vulnerability. A remote and unauthenticated attacker can append ";swagger-ui" to HTTP requests to bypass authentication and execute arbitrary Java on the victim server. Exploitation evidence was observed by the Shadowserver Foundation on 2025-02-05 UTC.

Affected products

  • Anji-Plus Report: before 1.4.1 (fixed in 1.4.1)

Published 2024-08-02. Last modified 2026-06-17.