Description
JeecgBoot up to v 3.5.1 was discovered to contain a SQL injection vulnerability via the component queryTableDictItemsByCode at org.jeecg.modules.api.controller.SystemApiController.
Remediation
References
https://github.com/jeecgboot/jeecg-boot/issues/4983
Related Vulnerabilities
CVE-2019-14862 Vulnerability in maven package li.rudin.mavenjs:knockout
CVE-2023-33546 Vulnerability in maven package org.codehaus.janino:janino-parent
CVE-2023-46731 Vulnerability in maven package org.xwiki.platform:xwiki-platform-administration-ui
CVE-2022-24431 Vulnerability in npm package abacus-ext-cmdline
CVE-2023-30530 Vulnerability in maven package org.jenkins-ci.plugins:consul-kv-builder