CVE-2023-24789: SQL Injection
Published Mar 6, 2023
·Updated
jeecg-boot v3.4.4 was discovered to contain an authenticated SQL injection vulnerability via the building block report component.
Affected Software
1 affected component
Jeecg jeecg=3.4.4
Event History
Mar 6, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is CVE-2023-24789?
CVE-2023-24789 is an authenticated SQL injection vulnerability in jeecg-boot v3.4.4.
2
How severe is CVE-2023-24789?
CVE-2023-24789 has a severity rating of 8.8 (high).
3
What software version is affected by CVE-2023-24789?
jeecg-boot v3.4.4 is affected by CVE-2023-24789.
4
How can I fix CVE-2023-24789?
To fix CVE-2023-24789, upgrade jeecg-boot to a version that doesn't contain the vulnerability.
5
Is there any reference for CVE-2023-24789?
Yes, you can find more information about CVE-2023-24789 at the following link: [https://github.com/jeecgboot/jeecg-boot/issues/4511](https://github.com/jeecgboot/jeecg-boot/issues/4511)