Description
Jeecg-boot v3.0 was discovered to contain a SQL injection vulnerability via the code parameter in /sys/user/queryUserComponentData.
Remediation
References
https://github.com/jeecgboot/jeecg-boot/issues/3348
Related Vulnerabilities
CVE-2016-10735 Vulnerability in maven package org.webjars.bower:bootstrap
CVE-2021-37578 Vulnerability in maven package org.apache.juddi:juddi-core
CVE-2023-32314 Vulnerability in maven package org.webjars.npm:vm2
CVE-2021-43821 Vulnerability in maven package org.opencastproject:opencast-ingest-service-impl
CVE-2023-40989 Vulnerability in maven package org.jeecgframework.boot:jeecg-boot-common