Show filters
38 Total Results
Displaying 21-30 of 38
Sort by:
Attacker Value
Unknown

CVE-2023-24789

Disclosure Date: March 06, 2023 (last updated February 24, 2025)
jeecg-boot v3.4.4 was discovered to contain an authenticated SQL injection vulnerability via the building block report component.
Attacker Value
Unknown

CVE-2021-37306

Disclosure Date: February 03, 2023 (last updated February 24, 2025)
An Insecure Permissions issue in jeecg-boot 2.4.5 and earlier allows remote attackers to gain escalated privilege and view sensitive information via api uri: api uri:/sys/user/checkOnlyUser?username=admin.
Attacker Value
Unknown

CVE-2021-37305

Disclosure Date: February 03, 2023 (last updated February 24, 2025)
An Insecure Permissions issue in jeecg-boot 2.4.5 and earlier allows remote attackers to gain escalated privilege and view sensitive information via api uri: /sys/user/querySysUser?username=admin.
Attacker Value
Unknown

CVE-2021-37304

Disclosure Date: February 03, 2023 (last updated February 24, 2025)
An Insecure Permissions issue in jeecg-boot 2.4.5 allows unauthenticated remote attackers to gain escalated privilege and view sensitive information via the httptrace interface.
Attacker Value
Unknown

CVE-2022-47105

Disclosure Date: January 19, 2023 (last updated February 24, 2025)
Jeecg-boot v3.4.4 was discovered to contain a SQL injection vulnerability via the component /sys/dict/queryTableData.
Attacker Value
Unknown

CVE-2022-45210

Disclosure Date: November 25, 2022 (last updated February 24, 2025)
Jeecg-boot v3.4.3 was discovered to contain a SQL injection vulnerability via the component /sys/user/deleteRecycleBin.
Attacker Value
Unknown

CVE-2022-45208

Disclosure Date: November 25, 2022 (last updated February 24, 2025)
Jeecg-boot v3.4.3 was discovered to contain a SQL injection vulnerability via the component /sys/user/putRecycleBin.
Attacker Value
Unknown

CVE-2022-45207

Disclosure Date: November 25, 2022 (last updated February 24, 2025)
Jeecg-boot v3.4.3 was discovered to contain a SQL injection vulnerability via the component updateNullByEmptyString.
Attacker Value
Unknown

CVE-2022-45206

Disclosure Date: November 25, 2022 (last updated February 24, 2025)
Jeecg-boot v3.4.3 was discovered to contain a SQL injection vulnerability via the component /sys/duplicate/check.
Attacker Value
Unknown

CVE-2022-45205

Disclosure Date: November 25, 2022 (last updated February 24, 2025)
Jeecg-boot v3.4.3 was discovered to contain a SQL injection vulnerability via the component /sys/dict/queryTableData.