First published: Fri Jun 16 2023(Updated: )
jeecg-boot 3.5.0 and 3.5.1 have a SQL injection vulnerability the id parameter of the /jeecg-boot/jmreport/show interface.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
JeecgBoot | =3.5.0 | |
JeecgBoot | =3.5.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2023-34659 is critical.
The affected software of CVE-2023-34659 is Jeecg Boot versions 3.5.0 and 3.5.1.
CVE-2023-34659 is a SQL injection vulnerability in the id parameter of the /jeecg-boot/jmreport/show interface in Jeecg Boot versions 3.5.0 and 3.5.1.
To fix CVE-2023-34659, update Jeecg Boot to a version that is not affected by the vulnerability.
More information about CVE-2023-34659 can be found at this link: https://github.com/jeecgboot/jeecg-boot/issues/4976