CVE-2022-27360: SQL Injection
SpringBlade v3.2.0 and below was discovered to contain a SQL injection vulnerability via the component customSqlSegment.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this SQL injection vulnerability?
The vulnerability ID is CVE-2022-27360.
What is the severity of CVE-2022-27360?
The severity of CVE-2022-27360 is critical with a severity value of 9.8.
Which version of SpringBlade is affected by CVE-2022-27360?
SpringBlade version 3.2.0 and below are affected by CVE-2022-27360.
How does CVE-2022-27360 exploit the vulnerability?
CVE-2022-27360 exploits the SQL injection vulnerability via the component customSqlSegment in SpringBlade.
Are there any references related to CVE-2022-27360?
Yes, there are references available for CVE-2022-27360. You can find them at the following links: - [Reference 1](https://forum.butian.net/share/1089) - [Reference 2](https://gitee.com/smallc/SpringBlade/blob/master/blade-service/blade-user/src/main/java/org/springblade/system/user/mapper/UserMapper.xml) - [Reference 3](https://saber.bladex.vip/#/login)