jeecg-boot qurestSql sql injection
82Vexday Risk Score
Corrige ahora. Ella explotación observada por VulnCheck y tiene exploit funcional público.
ssvc Actcvss 6.3epss 36%
de la publicación al arma25 días
Publicada en NVD17 mar
1ª PoC+25d
VulnCheck+253d
probabilidad de explotación
36%top 2% de las CVE
explotación observada
síVulnCheck
5 exploit(s) público(s)
A vulnerability classified as critical has been found in jeecg-boot 3.5.0. This affects an unknown part of the file jmreport/qurestSql. The manipulation of the argument apiSelectId leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-223299.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Productos afectados
n/a · jeecg-bootPoCs públicas encontradas — 5
vulncheckvulncheck.com/xdb/5e4c66849c79no verificadovulncheckvulncheck.com/xdb/24442d40d220no verificadovulncheckvulncheck.com/xdb/a9403b30a968no verificadovulncheckvulncheck.com/xdb/93887eb20164no verificadovulncheckvulncheck.com/xdb/94a9c476f691no verificado⚠ Recursos públicos, para evaluar la exposición de sistemas que controlas o estás autorizado a probar. Prueba solo con autorización.