Showing 7 vulnerabilities on this page for org.jeecgframework.boot:jeecg-boot-base

Signals CISA KEV Ransomware Nuclei
Maven vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

Insecure Permissions issue in jeecg-boot

An Insecure Permissions issue in jeecg-boot 2.4.5 and earlier allows remote attackers to gain escalated privilege and view sensitive information via api uri: /sys/user/querySysUser?username=admin.

CWE-732Feb 3, 20231 related artifact
CVSS7.5v3.1EPSS3.52%PoCs0SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX

Insecure Permissions issue in jeecg-boot

An Insecure Permissions issue in jeecg-boot 2.4.5 and earlier allows remote attackers to gain escalated privilege and view sensitive information via api uri: api uri:/sys/user/checkOnlyUser?username=admin.

CWE-732Feb 3, 2023
CVSS7.5v3.1EPSS0.801%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Insecure Permissions issue in jeecg-boot

An Insecure Permissions issue in jeecg-boot 2.4.5 allows unauthenticated remote attackers to gain escalated privilege and view sensitive information via the httptrace interface.

CWE-732Feb 3, 20231 related artifact
CVSS7.5v3.1EPSS4.01%PoCs0SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX

Cross-site Scripting in jeecg-boot

A Cross Site Scripting (XSS) vulnerabilitiy exits in jeecg-boot 3.0 in /jeecg-boot/jmreport/view with a mouseover event.

CWE-79Mar 10, 2022
CVSS6.1v3.1EPSS0.907%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

SQL Injection in Jeecg-boot

Jeecg-boot v3.0 was discovered to contain a SQL injection vulnerability via the code parameter in /sys/user/queryUserComponentData.

CWE-89Feb 16, 2022
CVSS9.8v3.1EPSS1.37%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

SQL Injection in Jeecg-boot

Jeecg-boot v3.0 was discovered to contain a SQL injection vulnerability via the code parameter in /jeecg-boot/sys/user/queryUserByDepId.

CWE-89Feb 16, 2022
CVSS9.8v3.1EPSS1.37%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

SQL Injection in JeecgBoot

In JeecgBoot 3.0, there is a SQL injection vulnerability that can operate the database with root privileges.

CWE-89Jan 25, 2022
CVSS9.8v3.1EPSS2%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX