Description
Jeecg-boot v3.0 was discovered to contain a SQL injection vulnerability via the code parameter in /jeecg-boot/sys/user/queryUserByDepId.
Remediation
References
https://github.com/jeecgboot/jeecg-boot/issues/3347
Related Vulnerabilities
CVE-2018-16487 Vulnerability in maven package org.webjars:lodash
CVE-2022-38545 Vulnerability in npm package valine
CVE-2020-8192 Vulnerability in npm package fastify
CVE-2021-23327 Vulnerability in maven package org.webjars.npm:apexcharts
CVE-2023-48796 Vulnerability in maven package org.apache.dolphinscheduler:dolphinscheduler-worker