CVE-2023-34659
jeecg-boot SQL injection vulnerability
Record summary
CVE-2023-34659 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.
Description
jeecg-boot 3.5.0 and 3.5.1 have a SQL injection vulnerability the id parameter of the /jeecg-boot/jmreport/show interface.
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Nov 27, 2023 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Dec 17, 2024 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
jeecg-bootBrowse jeecg / jeecg-boot | VulnCheck | Version data not supplied | |
org.jeecgframework.boot:jeecg-boot-parentBrowse Maven / org.jeecgframework.boot:jeecg-boot-parent | GitHub Advisory | 3.5.0 to ≤ 3.5.1 | affected |
Nuclei templates
1ProjectDiscoveryCRITICALJeecgBoot 3.5.0 - SQL InjectionCVSS 9.8
jeecg-boot 3.5.0 and 3.5.1 have a SQL injection vulnerability the id parameter of the /jeecg-boot/jmreport/show interface.
Impact
Successful exploitation of this vulnerability could allow an attacker to execute arbitrary SQL queries, potentially leading to unauthorized access, data leakage, or data manipulation.
Remediation
Upgrade JeecgBoot to a patched version or apply the necessary security patches provided by the vendor.
Source: ProjectDiscovery