First published: Sat Dec 30 2023(Updated: )
SQL injection vulnerability in jeecg-boot version 3.5.3, allows remote attackers to escalate privileges and obtain sensitive information via the jmreport/qurestSql component.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
maven/org.jeecgframework.boot:jeecg-boot-common | <=3.5.3 | |
JeecgBoot | <=3.5.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-41542 is considered a high-severity vulnerability due to its potential for privilege escalation and data exposure.
To mitigate CVE-2023-41542, upgrade jeecg-boot to a version later than 3.5.3 to ensure the SQL injection vulnerability is patched.
CVE-2023-41542 affects the jmreport/qurestSql component within jeecg-boot version 3.5.3.
CVE-2023-41542 can be exploited by remote attackers with certain access to the affected system.
CVE-2023-41542 is classified as an SQL injection vulnerability, enabling attackers to manipulate SQL queries.