CVE-2023-34602

MEDIUM6.5EPSS 0.45%

JeecgBoot vulnerable to SQL injection in queryTableDictItemsByCode

發布日:2023/6/19修改日:2023/11/8

描述

JeecgBoot up to v 3.5.1 was discovered to contain a SQL injection vulnerability via the component `queryTableDictItemsByCode` in method `org.jeecg.modules.api.controller.SystemApiController`.

受影響套件(1)

CVSS 分數

來源版本嚴重程度向量
osvCVSS 3.1MEDIUM6.5CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

參考連結(4)