In `EAMS/eams-framework/src/main/java/com/dimple/framework/config/ShiroConfig.java` we can find a fixed key and uses this key to encrypt the rememberMe parameter in the cookie. It will cause deserialization vulnerability [![xoSgmT.png](https://s1.ax1x.com/2022/10/30/xoSgmT.png)](https://imgse.com/i/xoSgmT) I set up a...