Page 2 of 24 results (0.007 seconds)

CVSS: 9.8EPSS: 0%CPEs: 1EXPL: 1

31 Mar 2023 — A vulnerability was found in jeecg-boot 3.5.0 and classified as critical. This issue affects some unknown processing of the component API Documentation. The manipulation leads to improper authentication. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. • https://note.youdao.com/ynoteshare/index.html?id=7eb8fc804ea3544d8add43749a09173e • CWE-287: Improper Authentication •

CVSS: 9.8EPSS: 0%CPEs: 1EXPL: 1

30 Mar 2023 — A vulnerability was found in jeecg-boot 3.5.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file SysDictMapper.java of the component Sleep Command Handler. The manipulation leads to sql injection. The attack can be launched remotely. • https://github.com/private-null/report/blob/main/README.md • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •

CVSS: 10.0EPSS: 0%CPEs: 1EXPL: 1

19 Jan 2023 — Jeecg-boot v3.4.4 was discovered to contain a SQL injection vulnerability via the component /sys/dict/queryTableData. Se descubrió que Jeecg-boot v3.4.4 contiene una vulnerabilidad de inyección SQL a través del componente /sys/dict/queryTableData. • https://github.com/jeecgboot/jeecg-boot/issues/4393 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •

CVSS: 5.3EPSS: 0%CPEs: 1EXPL: 1

25 Nov 2022 — Jeecg-boot v3.4.3 was discovered to contain a SQL injection vulnerability via the component /sys/dict/queryTableData. Se descubrió que Jeecg-boot v3.4.3 contiene una vulnerabilidad de inyección SQL a través del componente /sys/dict/queryTableData. • http://jeecg-boot.com • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •

CVSS: 10.0EPSS: 0%CPEs: 1EXPL: 1

25 Nov 2022 — Jeecg-boot v3.4.3 was discovered to contain a SQL injection vulnerability via the component /sys/duplicate/check. Se descubrió que Jeecg-boot v3.4.3 contiene una vulnerabilidad de inyección SQL a través del componente /sys/duplicate/check. • http://jeecg-boot.com • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •

CVSS: 10.0EPSS: 0%CPEs: 1EXPL: 1

25 Nov 2022 — Jeecg-boot v3.4.3 was discovered to contain a SQL injection vulnerability via the component updateNullByEmptyString. Se descubrió que Jeecg-boot v3.4.3 contiene una vulnerabilidad de inyección SQL a través del componente updateNullByEmptyString. • http://jeecg-boot.com • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •

CVSS: 4.3EPSS: 0%CPEs: 1EXPL: 1

25 Nov 2022 — Jeecg-boot v3.4.3 was discovered to contain a SQL injection vulnerability via the component /sys/user/putRecycleBin. Se descubrió que Jeecg-boot v3.4.3 contiene una vulnerabilidad de inyección SQL a través del componente /sys/user/putRecycleBin. • http://jeecg-boot.com • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •

CVSS: 4.3EPSS: 0%CPEs: 1EXPL: 1

25 Nov 2022 — Jeecg-boot v3.4.3 was discovered to contain a SQL injection vulnerability via the component /sys/user/deleteRecycleBin. Se descubrió que Jeecg-boot v3.4.3 contiene una vulnerabilidad de inyección SQL a través del componente /sys/user/deleteRecycleBin. • http://jeecg-boot.com • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •

CVSS: 6.1EPSS: 0%CPEs: 1EXPL: 1

10 Mar 2022 — A Cross Site Scripting (XSS) vulnerabilitiy exits in jeecg-boot 3.0 in /jeecg-boot/jmreport/view with a mouseover event. Se presenta una vulnerabilidad de tipo Cross Site Scripting (XSS) en jeecg-boot versión 3.0, en /jeecg-boot/jmreport/view con un evento de mouseover • https://github.com/jeecgboot/jeecg-boot/issues/3223 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 9.8EPSS: 0%CPEs: 1EXPL: 1

16 Feb 2022 — Jeecg-boot v3.0 was discovered to contain a SQL injection vulnerability via the code parameter in /jeecg-boot/sys/user/queryUserByDepId. Se ha detectado que Jeecg-boot versión v3.0, contiene una vulnerabilidad de inyección SQL por medio del parámetro code en /jeecg-boot/sys/user/queryUserByDepId • https://github.com/jeecgboot/jeecg-boot/issues/3347 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •