CVE-2023-34659: SQL Injection
Published Jun 16, 2023
·Updated
jeecg-boot 3.5.0 and 3.5.1 have a SQL injection vulnerability the id parameter of the /jeecg-boot/jmreport/show interface.
Affected Software
2 affected components
Jeecg jeecg boot=3.5.0
Jeecg jeecg boot=3.5.1
Event History
Jun 16, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-34659?
The severity of CVE-2023-34659 is critical.
2
What is the affected software of CVE-2023-34659?
The affected software of CVE-2023-34659 is Jeecg Boot versions 3.5.0 and 3.5.1.
3
What is the vulnerability description of CVE-2023-34659?
CVE-2023-34659 is a SQL injection vulnerability in the id parameter of the /jeecg-boot/jmreport/show interface in Jeecg Boot versions 3.5.0 and 3.5.1.
4
How can I fix CVE-2023-34659?
To fix CVE-2023-34659, update Jeecg Boot to a version that is not affected by the vulnerability.
5
Where can I find more information about CVE-2023-34659?
More information about CVE-2023-34659 can be found at this link: https://github.com/jeecgboot/jeecg-boot/issues/4976