CVE-2022-22880: SQL Injection
Published Feb 16, 2022
·Updated
Jeecg-boot v3.0 was discovered to contain a SQL injection vulnerability via the code parameter in /jeecg-boot/sys/user/queryUserByDepId.
Affected Software
1 affected component
Jeecg jeecg boot<=3.0
Event History
Feb 16, 2022
CVE Published
via MITRE·09:42 PM
Data Sourced
via MITRE·09:42 PM
Description
Frequently Asked Questions
1
What is CVE-2022-22880?
CVE-2022-22880 is a SQL injection vulnerability in Jeecg-boot v3.0.
2
How does the SQL injection vulnerability in Jeecg-boot v3.0 occur?
The SQL injection vulnerability occurs via the code parameter in /jeecg-boot/sys/user/queryUserByDepId.
3
What is the severity of CVE-2022-22880?
CVE-2022-22880 has a severity rating of critical.
4
How can I fix the SQL injection vulnerability in Jeecg-boot v3.0?
To fix the SQL injection vulnerability, update Jeecg-boot to a version that addresses the issue.
5
Where can I find more information about CVE-2022-22880?
You can find more information about CVE-2022-22880 at the following link: [GitHub Issue](https://github.com/jeecgboot/jeecg-boot/issues/3347).