[MAVEN:GHSA-F9PG-G9XW-R5G2] SQL Injection in Jeecg-boot

Severity Critical
Affected Packages 2
CVEs 1

Jeecg-boot v3.0 was discovered to contain a SQL injection vulnerability via the code parameter in /sys/user/queryUserComponentData.

ID
MAVEN:GHSA-F9PG-G9XW-R5G2
Severity
critical
URL
https://github.com/advisories/GHSA-f9pg-g9xw-r5g2
Published
2022-02-17T00:00:25
(2 years ago)
Modified
2023-02-03T05:06:17
(19 months ago)
Rights
Maven Security Team
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:maven/org.jeecgframework.boot/jeecg-boot-base-core org.jeecgframework.boot jeecg-boot-base-core <= 3.0
Affected pkg:maven/org.jeecgframework.boot/jeecg-boot-base org.jeecgframework.boot jeecg-boot-base <= 3.0
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...