There is an injection vulnerability in jeecg boot versions 3.0.0 to 3.5.3 due to lax character filtering, which allows attackers to execute arbitrary code on components through specially crafted HTTP requests.
Attack Parameters
Impact Assessment
CVSS Vector v3.1
Weakness Type (CWE)
Vulnerable Products 1
| Configuration | From (including) | Up to (excluding) |
|---|---|---|
|
Jeecg Jeecg_Boot
cpe:2.3:a:jeecg:jeecg_boot:*:*:*:*:*:*:*:*
|
3.0
|
<= 3.5.3
|