CVE-2023-38905: SQL Injection
SQL injection vulnerability in Jeecg-boot v.3.5.0 and before allows a local attacker to cause a denial of service via the Benchmark, PGSleep, DBMSLock.Sleep, Waitfor, DECODE, and DBMSPIPE.RECEIVEMESSAGE functions.
Other sources
SQL injection vulnerability in Jeecg-boot v.3.5.0 and before allows a local attacker to cause a denial of service via the Benchmark, PGSleep, DBMSLock.Sleep, Waitfor, DECODE, and DBMSPIPE.RECEIVEMESSAGE functions.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2023-38905.
What is the severity of CVE-2023-38905?
CVE-2023-38905 has a severity rating of 5.5 (medium).
How does the SQL injection vulnerability in Jeecg-boot v.3.5.0 and before work?
The SQL injection vulnerability allows a local attacker to cause a denial of service by exploiting certain functions in Jeecg-boot, such as `Benchmark`, `PG_Sleep`, `DBMS_Lock.Sleep`, `Waitfor`, `DECODE`, and `DBMS_PIPE.RECEIVE_MESSAGE`.
What software versions are affected by CVE-2023-38905?
Jeecg-boot v.3.5.0 and earlier versions are affected by CVE-2023-38905.
Are there any references for CVE-2023-38905?
Yes, you can find more information about CVE-2023-38905 in the following references: [1](https://gist.github.com/wealeson1/e24fc8575f4e051320d69e9a75080642), [2](https://github.com/jeecgboot/jeecg-boot/issues/4737), [3](https://nvd.nist.gov/vuln/detail/CVE-2023-38905).