Description
jeecg-boot 3.5.0 and 3.5.1 have a SQL injection vulnerability the id parameter of the /jeecg-boot/jmreport/show interface.
Remediation
References
https://github.com/jeecgboot/jeecg-boot/issues/4976
Related Vulnerabilities
CVE-2019-20174 Vulnerability in maven package org.webjars.npm:auth0-lock
CVE-2018-6464 Vulnerability in maven package org.webjars:simditor
CVE-2023-26118 Vulnerability in npm package angular
CVE-2021-46384 Vulnerability in maven package net.mingsoft:ms-mcms
CVE-2022-37767 Vulnerability in maven package io.pebbletemplates:pebble