CVE-2023-34602: SQL Injection
JeecgBoot up to v 3.5.1 was discovered to contain a SQL injection vulnerability via the component queryTableDictItemsByCode in method org.jeecg.modules.api.controller.SystemApiController.
Other sources
JeecgBoot up to v 3.5.1 was discovered to contain a SQL injection vulnerability via the component queryTableDictItemsByCode at org.jeecg.modules.api.controller.SystemApiController.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
maven/org.jeecgframework.boot:jeecg-boot-parentto a version that resolves this vulnerability.Fixed in 3.5.1
Event History
Frequently Asked Questions
What is the vulnerability ID of this issue?
The vulnerability ID of this issue is CVE-2023-34602.
What is the severity of CVE-2023-34602?
The severity of CVE-2023-34602 is high with a CVSS score of 7.5.
How can this vulnerability be exploited?
This vulnerability can be exploited through a SQL injection attack via the component queryTableDictItemsByCode in the SystemApiController of JeecgBoot up to version 3.5.1.
How can I fix CVE-2023-34602?
To fix CVE-2023-34602, update JeecgBoot to a version higher than 3.5.1 that contains a patch for the SQL injection vulnerability.
Where can I find more information about CVE-2023-34602?
You can find more information about CVE-2023-34602 on the GitHub page of JeecgBoot: https://github.com/jeecgboot/jeecg-boot/issues/4983.