Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
JeecgBoot versions from 3.4.3 up to 3.8.0 were found to contain a SQL injection vulnerability in the /jeecg-boot/online/cgreport/head/parseSql endpoint, which allows bypassing SQL blacklist restrictions.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
JeecgBoot 安全漏洞
Vulnerability Description
JeecgBoot是中国国炬(Jeecg)公司的一个适用于企业 Web 应用程序的 Java 低代码平台。 JeecgBoot 3.4.3至3.8.0版本存在安全漏洞,该漏洞源于/jeecg-boot/online/cgreport/head/parseSql端点存在SQL注入漏洞,可能导致绕过SQL黑名单限制。
CVSS Information
N/A
Vulnerability Type
N/A