PT-2026-23883 · Unknown · Jeecg-Boot
CVSS v2.0
6.5
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
JeecgBoot versions up to 3.9.1
Description
A flaw exists within JeecgBoot that allows for SQL injection. This issue is located in the
isExistSqlInjectKeyword function within the /jeecg-boot/sys/api/getDictItems file. Successful exploitation could occur remotely. The details of the exploit have been publicly disclosed.Recommendations
Update JeecgBoot to a version beyond 3.9.1.
Exploit
Fix
Special Elements Injection
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Jeecg-Boot