JSONPath-plus.CVE-2025-1302.Remote.Code.Execution
Description
This indicates a possible attack against a Remote Code Execution vulnerability in JSONPath-plus package.
The vulnerability is due to lack of input validation when handling requests. A remote attacker can exploit this vulnerability by sending maliciously crafted requests to the vulnerable server. Successful exploitation could result in arbitrary code execution in the security context of the application.
Affected Products
jsonpath-plus versions before 10.3.0
Impact
System Compromise: Remote attackers can gain control of vulnerable systems.
Recommended Actions
Apply the most recent upgrade or patch from the vendor.
https://github.com/JSONPath-Plus/JSONPath/commit/30942896d27cb8a806b965a5ca9ef9f686be24ee
Coverage
| IPS (Regular DB) | |
| IPS (Extended DB) |