First published: Wed Feb 16 2022(Updated: )
Jeecg-boot v3.0 was discovered to contain a SQL injection vulnerability via the code parameter in /jeecg-boot/sys/user/queryUserByDepId.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Jeecg Jeecg Boot | <=3.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-22880 is a SQL injection vulnerability in Jeecg-boot v3.0.
The SQL injection vulnerability occurs via the code parameter in /jeecg-boot/sys/user/queryUserByDepId.
CVE-2022-22880 has a severity rating of critical.
To fix the SQL injection vulnerability, update Jeecg-boot to a version that addresses the issue.
You can find more information about CVE-2022-22880 at the following link: [GitHub Issue](https://github.com/jeecgboot/jeecg-boot/issues/3347).