logo

CVE-2023-34659 org.jeecgframework.boot:jeecg-boot-parent

Package

Manager: maven
Name: org.jeecgframework.boot:jeecg-boot-parent
Vulnerable Version: >=3.5.0 <=3.5.1

Severity

Level: Critical

CVSS v3.1: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

EPSS: 0.91195 pctl0.99638

Details

jeecg-boot SQL injection vulnerability jeecg-boot 3.5.0 and 3.5.1 have a SQL injection vulnerability the `id` parameter of the `/jeecg-boot/jmreport/show` interface.

Metadata

Created: 2023-06-16T18:30:33Z
Modified: 2023-06-27T18:38:11Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/06/GHSA-934g-fvcc-4833/GHSA-934g-fvcc-4833.json
CWE IDs: ["CWE-89"]
Alternative ID: GHSA-934g-fvcc-4833
Finding: F297
Auto approve: 1