Show filters
37 Total Results
Displaying 1-10 of 37
Sort by:
Attacker Value
Unknown

CVE-2023-49442

Disclosure Date: January 03, 2024 (last updated February 25, 2025)
Deserialization of Untrusted Data in jeecgFormDemoController in JEECG 4.0 and earlier allows attackers to run arbitrary code via crafted POST request.
Attacker Value
Unknown

CVE-2023-41544

Disclosure Date: December 30, 2023 (last updated February 25, 2025)
SSTI injection vulnerability in jeecg-boot version 3.5.3, allows remote attackers to execute arbitrary code via crafted HTTP request to the /jmreport/loadTableData component.
Attacker Value
Unknown

CVE-2023-41543

Disclosure Date: December 30, 2023 (last updated February 25, 2025)
SQL injection vulnerability in jeecg-boot v3.5.3, allows remote attackers to escalate privileges and obtain sensitive information via the component /sys/replicate/check.
Attacker Value
Unknown

CVE-2023-41542

Disclosure Date: December 30, 2023 (last updated February 25, 2025)
SQL injection vulnerability in jeecg-boot version 3.5.3, allows remote attackers to escalate privileges and obtain sensitive information via the jmreport/qurestSql component.
Attacker Value
Unknown

CVE-2023-47467

Disclosure Date: November 22, 2023 (last updated February 25, 2025)
Directory Traversal vulnerability in jeecg-boot v.3.6.0 allows a remote privileged attacker to obtain sensitive information via the file directory structure.
Attacker Value
Unknown

CVE-2023-40989

Disclosure Date: September 22, 2023 (last updated February 25, 2025)
SQL injection vulnerbility in jeecgboot jeecg-boot v 3.0, 3.5.3 that allows a remote attacker to execute arbitrary code via a crafted request to the report/jeecgboot/jmreport/queryFieldBySql component.
Attacker Value
Unknown

CVE-2023-42268

Disclosure Date: September 08, 2023 (last updated February 25, 2025)
Jeecg boot up to v3.5.3 was discovered to contain a SQL injection vulnerability via the component /jeecg-boot/jmreport/show.
Attacker Value
Unknown

CVE-2023-41578

Disclosure Date: September 08, 2023 (last updated February 25, 2025)
Jeecg boot up to v3.5.3 was discovered to contain an arbitrary file read vulnerability via the interface /testConnection.
Attacker Value
Unknown

CVE-2023-38905

Disclosure Date: August 17, 2023 (last updated February 25, 2025)
SQL injection vulnerability in Jeecg-boot v.3.5.0 and before allows a local attacker to cause a denial of service via the Benchmark, PG_Sleep, DBMS_Lock.Sleep, Waitfor, DECODE, and DBMS_PIPE.RECEIVE_MESSAGE functions.
Attacker Value
Unknown

CVE-2023-38992

Disclosure Date: July 28, 2023 (last updated February 25, 2025)
jeecg-boot v3.5.1 was discovered to contain a SQL injection vulnerability via the title parameter at /sys/dict/loadTreeData.