jeecg-boot qurestSql sql injection
82Vexday Risk Score
Patch now. It exploitation observed by VulnCheck and has a working public exploit.
ssvc Actcvss 6.3epss 36%
from disclosure to weapon25 days
Published on NVDMar 17
1st PoC+25d
VulnCheck+253d
exploitation probability
36%top 2% of all CVEs
observed exploitation
yesVulnCheck
5 public exploit(s)
A vulnerability classified as critical has been found in jeecg-boot 3.5.0. This affects an unknown part of the file jmreport/qurestSql. The manipulation of the argument apiSelectId leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-223299.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Affected products
n/a · jeecg-bootpublic PoCs found — 5
vulncheckvulncheck.com/xdb/5e4c66849c79unverifiedvulncheckvulncheck.com/xdb/24442d40d220unverifiedvulncheckvulncheck.com/xdb/a9403b30a968unverifiedvulncheckvulncheck.com/xdb/93887eb20164unverifiedvulncheckvulncheck.com/xdb/94a9c476f691unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.