Description
jeecg-boot v3.5.1 was discovered to contain a SQL injection vulnerability via the title parameter at /sys/dict/loadTreeData.
Remediation
References
https://github.com/jeecgboot/jeecg-boot/issues/5173
Related Vulnerabilities
CVE-2020-7748 Vulnerability in npm package @tsed/core
CVE-2023-49620 Vulnerability in maven package org.apache.dolphinscheduler:dolphinscheduler-dao
CVE-2022-25857 Vulnerability in maven package org.yaml:snakeyaml
CVE-2021-23436 Vulnerability in npm package immer
CVE-2016-4437 Vulnerability in maven package org.apache.shiro:shiro-core