Description
JeecgBoot up to v 3.5.1 was discovered to contain a SQL injection vulnerability via the component queryFilterTableDictInfo at org.jeecg.modules.api.controller.SystemApiController.
Remediation
References
https://github.com/jeecgboot/jeecg-boot/issues/4984
Related Vulnerabilities
CVE-2020-28481 Vulnerability in maven package org.webjars.bower:socket.io
CVE-2021-21353 Vulnerability in npm package pug
CVE-2019-9827 Vulnerability in maven package io.hawt:hawtio-system
CVE-2023-40037 Vulnerability in maven package org.apache.nifi:nifi-jms-processors
CVE-2023-36820 Vulnerability in maven package io.micronaut.security:micronaut-security-oauth2