Description
jeecg-boot 3.5.0 and 3.5.1 have a SQL injection vulnerability the id parameter of the /jeecg-boot/jmreport/show interface.
Remediation
References
https://github.com/jeecgboot/jeecg-boot/issues/4976
Related Vulnerabilities
CVE-2022-41226 Vulnerability in maven package com.compuware.jenkins:compuware-common-configuration
CVE-2022-45382 Vulnerability in maven package org.jenkins-ci.plugins:naginator
CVE-2018-20094 Vulnerability in maven package com.xuxueli:xxl-conf
CVE-2023-34603 Vulnerability in maven package org.jeecgframework.boot:jeecg-boot-parent