CVE-2023-1784 – jeecg-boot API Documentation improper authentication
https://notcve.org/view.php?id=CVE-2023-1784
31 Mar 2023 — A vulnerability was found in jeecg-boot 3.5.0 and classified as critical. This issue affects some unknown processing of the component API Documentation. The manipulation leads to improper authentication. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. • https://note.youdao.com/ynoteshare/index.html?id=7eb8fc804ea3544d8add43749a09173e • CWE-287: Improper Authentication •
CVE-2023-1741 – jeecg-boot Sleep Command SysDictMapper.java sql injection
https://notcve.org/view.php?id=CVE-2023-1741
30 Mar 2023 — A vulnerability was found in jeecg-boot 3.5.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file SysDictMapper.java of the component Sleep Command Handler. The manipulation leads to sql injection. The attack can be launched remotely. • https://github.com/private-null/report/blob/main/README.md • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •
CVE-2022-47105
https://notcve.org/view.php?id=CVE-2022-47105
19 Jan 2023 — Jeecg-boot v3.4.4 was discovered to contain a SQL injection vulnerability via the component /sys/dict/queryTableData. Se descubrió que Jeecg-boot v3.4.4 contiene una vulnerabilidad de inyección SQL a través del componente /sys/dict/queryTableData. • https://github.com/jeecgboot/jeecg-boot/issues/4393 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •
CVE-2022-45205
https://notcve.org/view.php?id=CVE-2022-45205
25 Nov 2022 — Jeecg-boot v3.4.3 was discovered to contain a SQL injection vulnerability via the component /sys/dict/queryTableData. Se descubrió que Jeecg-boot v3.4.3 contiene una vulnerabilidad de inyección SQL a través del componente /sys/dict/queryTableData. • http://jeecg-boot.com • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •
CVE-2022-45206
https://notcve.org/view.php?id=CVE-2022-45206
25 Nov 2022 — Jeecg-boot v3.4.3 was discovered to contain a SQL injection vulnerability via the component /sys/duplicate/check. Se descubrió que Jeecg-boot v3.4.3 contiene una vulnerabilidad de inyección SQL a través del componente /sys/duplicate/check. • http://jeecg-boot.com • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •
CVE-2022-45207
https://notcve.org/view.php?id=CVE-2022-45207
25 Nov 2022 — Jeecg-boot v3.4.3 was discovered to contain a SQL injection vulnerability via the component updateNullByEmptyString. Se descubrió que Jeecg-boot v3.4.3 contiene una vulnerabilidad de inyección SQL a través del componente updateNullByEmptyString. • http://jeecg-boot.com • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •
CVE-2022-45208
https://notcve.org/view.php?id=CVE-2022-45208
25 Nov 2022 — Jeecg-boot v3.4.3 was discovered to contain a SQL injection vulnerability via the component /sys/user/putRecycleBin. Se descubrió que Jeecg-boot v3.4.3 contiene una vulnerabilidad de inyección SQL a través del componente /sys/user/putRecycleBin. • http://jeecg-boot.com • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •
CVE-2022-45210
https://notcve.org/view.php?id=CVE-2022-45210
25 Nov 2022 — Jeecg-boot v3.4.3 was discovered to contain a SQL injection vulnerability via the component /sys/user/deleteRecycleBin. Se descubrió que Jeecg-boot v3.4.3 contiene una vulnerabilidad de inyección SQL a través del componente /sys/user/deleteRecycleBin. • http://jeecg-boot.com • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •
CVE-2021-44585
https://notcve.org/view.php?id=CVE-2021-44585
10 Mar 2022 — A Cross Site Scripting (XSS) vulnerabilitiy exits in jeecg-boot 3.0 in /jeecg-boot/jmreport/view with a mouseover event. Se presenta una vulnerabilidad de tipo Cross Site Scripting (XSS) en jeecg-boot versión 3.0, en /jeecg-boot/jmreport/view con un evento de mouseover • https://github.com/jeecgboot/jeecg-boot/issues/3223 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2022-22880
https://notcve.org/view.php?id=CVE-2022-22880
16 Feb 2022 — Jeecg-boot v3.0 was discovered to contain a SQL injection vulnerability via the code parameter in /jeecg-boot/sys/user/queryUserByDepId. Se ha detectado que Jeecg-boot versión v3.0, contiene una vulnerabilidad de inyección SQL por medio del parámetro code en /jeecg-boot/sys/user/queryUserByDepId • https://github.com/jeecgboot/jeecg-boot/issues/3347 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •