VulnerabilityModified
CVE-2023-1454
A vulnerability classified as critical has been found in jeecg-boot 3.5.0.
CRITICAL 9.8EPSS 35.8%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 35.8%, higher than 98% of all known CVEs. Patch or mitigate before the next change window.
Description
A vulnerability classified as critical has been found in jeecg-boot 3.5.0. This affects an unknown part of the file jmreport/qurestSql. The manipulation of the argument apiSelectId leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-223299.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 35.83% probability · 98th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-89
- Affected
- jeecg/jeecg boot
- Source
- cna@vuldb.com
References
- https://github.com/J0hnWalker/jeecg-boot-sqliExploit, Third Party Advisory
- https://vuldb.com/?ctiid.223299Permissions Required, Third Party Advisory, VDB Entry
- https://vuldb.com/?id.223299Third Party Advisory, VDB Entry
- https://github.com/J0hnWalker/jeecg-boot-sqliExploit, Third Party Advisory
- https://vuldb.com/?ctiid.223299Permissions Required, Third Party Advisory, VDB Entry
- https://vuldb.com/?id.223299Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.