First published: Tue Jan 31 2023(Updated: )
SQL Inection vulnerability in Dromara hutool before 5.8.21 allows attacker to execute arbitrary code via the aviator template engine.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Hutool Hutool | =5.8.11 | |
maven/cn.hutool:hutool-all | <5.8.21 | 5.8.21 |
Hutool Hutool | <5.8.21 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this SQL Injection vulnerability is CVE-2023-24163.
The title of this SQL Injection vulnerability is 'SQL Injection vulnerability in Dromara hutool v5.8.11 allows attacker to execute arbitrary code via the aviator template engine.'
The affected software version is Hutool Hutool v5.8.11.
The severity of this SQL Injection vulnerability is critical.
An attacker can exploit this vulnerability by executing arbitrary code via the aviator template engine.
Please refer to the reference link for information on how to fix this vulnerability.