First published: Fri Feb 07 2025(Updated: )
SQL injection vulnerability in Beijing Guoju Information Technology Co., Ltd JeecgBoot v.3.7.2 allows a remote attacker to obtain sensitive information via the getTotalData component.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
JeecgBoot | ||
maven/org.jeecgframework.boot:jeecg-boot-common | <=3.7.2 | 3.7.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-57606 is classified as a high severity vulnerability due to its potential to allow remote attackers access to sensitive information.
To fix CVE-2024-57606, upgrade the JeecgBoot software to version 3.7.3 or later.
CVE-2024-57606 is an SQL injection vulnerability that affects the getTotalData component.
Yes, CVE-2024-57606 can be exploited remotely by attackers targeting the affected JeecgBoot application.
CVE-2024-57606 affects JeecgBoot versions up to and including 3.7.2.