CVE-2025-60268: Huayi-Tec Jeewms

Medium severity, CVSS 6.5. EPSS: 0.4% chance of exploitation in the next 30 days.

An arbitrary file upload vulnerability exists in JeeWMS 20250820, which is caused by the lack of file checking in the saveFiles function in /jeewms/cgUploadController.do. An attacker with normal privileges was able to upload a malicious file that would lead to remote code execution.

Affected products

Published 2025-10-10. Last modified 2026-06-17.