First published: Fri Nov 25 2022(Updated: )
Jeecg-boot v3.4.3 was discovered to contain a SQL injection vulnerability via the component /sys/dict/queryTableData.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Jeecg Jeecg Boot | =3.4.3 | |
=3.4.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-45205 is a SQL injection vulnerability in Jeecg-boot v3.4.3 via the component /sys/dict/queryTableData.
CVE-2022-45205 has a severity rating of 5.3, which is considered medium.
CVE-2022-45205 affects Jeecg-boot v3.4.3 and allows SQL injection through the /sys/dict/queryTableData component.
The CWE ID for CVE-2022-45205 is 89, which corresponds to Improper Neutralization of Special Elements in Output Used by a Downstream Component Injection.
There is currently no fix available for CVE-2022-45205, but it is recommended to upgrade to a patched version once it becomes available.