Description
JeecgBoot up to v 3.5.1 was discovered to contain a SQL injection vulnerability via the component queryTableDictItemsByCode at org.jeecg.modules.api.controller.SystemApiController.
Remediation
References
https://github.com/jeecgboot/jeecg-boot/issues/4983
Related Vulnerabilities
CVE-2017-18197 Vulnerability in npm package mxgraph
CVE-2018-3739 Vulnerability in maven package org.webjars.npm:https-proxy-agent
CVE-2023-33950 Vulnerability in maven package com.liferay.portal:release.portal.bom
CVE-2022-21803 Vulnerability in npm package nconf
CVE-2023-26048 Vulnerability in maven package org.eclipse.jetty:jetty-server