A vulnerability classified as critical has been found in jeecg-boot 3.5.0. This affects an unknown part of the file jmreport/qurestSql. The manipulation of the argument apiSelectId leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-223299.
References
Link Resource
https://github.com/J0hnWalker/jeecg-boot-sqli Exploit Third Party Advisory
https://vuldb.com/?ctiid.223299 Permissions Required Third Party Advisory VDB Entry
https://vuldb.com/?id.223299 Third Party Advisory VDB Entry
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: VulDB

Published: 2023-03-17T06:56:08.267Z

Updated: 2024-02-13T07:56:27.604Z

Reserved: 2023-03-17T06:55:40.345Z


Link: CVE-2023-1454

JSON object: View

cve-icon NVD Information

Status : Modified

Published: 2023-03-17T07:15:13.573

Modified: 2024-05-17T02:18:06.880


Link: CVE-2023-1454

JSON object: View

cve-icon Redhat Information

No data.

CWE