RSS   Vulnerabilities for 'Jeecg boot'   RSS

2022-03-10
 
CVE-2021-44585

CWE-79
 

 
A Cross Site Scripting (XSS) vulnerabilitiy exits in jeecg-boot 3.0 in /jeecg-boot/jmreport/view with a mouseover event.

 
2022-02-16
 
CVE-2022-22880

CWE-89
 

 
Jeecg-boot v3.0 was discovered to contain a SQL injection vulnerability via the code parameter in /jeecg-boot/sys/user/queryUserByDepId.

 
 
CVE-2022-22881

CWE-89
 

 
Jeecg-boot v3.0 was discovered to contain a SQL injection vulnerability via the code parameter in /sys/user/queryUserComponentData.

 
2022-01-25
 
CVE-2021-46089

CWE-89
 

 
In JeecgBoot 3.0, there is a SQL injection vulnerability that can operate the database with root privileges.

 
2021-08-06
 
CVE-2020-28087

CWE-89
 

 
A SQL injection vulnerability in /jeecg boot/sys/dict/loadtreedata of jeecg-boot CMS 2.3 allows attackers to access sensitive database information.

 
 
CVE-2020-28088

CWE-434
 

 
An arbitrary file upload vulnerability in /jeecg-boot/sys/common/upload of jeecg-boot CMS 2.3 allows attackers to execute arbitrary code.

 


Copyright 2024, cxsecurity.com

 

Back to Top