Record summary

CVE-2023-34659 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.

Description

jeecg-boot 3.5.0 and 3.5.1 have a SQL injection vulnerability the id parameter of the /jeecg-boot/jmreport/show interface.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Nov 27, 2023 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationPoC
AutomatableYes
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Dec 17, 2024 · Source: CVE List

Affected products and versions

2
ProductSourceVersion rangeStatus
VulnCheckVersion data not supplied

org.jeecgframework.boot:jeecg-boot-parent

Browse Maven / org.jeecgframework.boot:jeecg-boot-parent
GitHub Advisory3.5.0 to ≤ 3.5.1affected

Nuclei templates

1
ProjectDiscoveryCRITICALJeecgBoot 3.5.0 - SQL InjectionCVSS 9.8

jeecg-boot 3.5.0 and 3.5.1 have a SQL injection vulnerability the id parameter of the /jeecg-boot/jmreport/show interface.

Impact

Successful exploitation of this vulnerability could allow an attacker to execute arbitrary SQL queries, potentially leading to unauthorized access, data leakage, or data manipulation.

Remediation

Upgrade JeecgBoot to a patched version or apply the necessary security patches provided by the vendor.

WeaknessesCWE-89
Authorsritikchaddha
Template tagscve2023cvejeecgsqlivkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:a:jeecg:jeecg_boot:3.5.0:*:*:*:*:*:*:*
Shodan: http.favicon.hash:1380908726
FOFA: icon_hash=1380908726

Source: ProjectDiscovery

References

3