SQL Injection Vulnerability in MyBatis Plus by Baomidou
CVE-2022-25517
9.8CRITICAL
What is CVE-2022-25517?
MyBatis Plus version 3.4.3 contains a SQL injection vulnerability that can be exploited through the Column parameter in the AbstractWrapper.java file. Attackers could potentially execute arbitrary SQL commands by manipulating this parameter, which poses a significant security threat. The vendor contends that the execution of a SQL statement was intended as a feature; however, the implications of this vulnerability require immediate attention and potential remediation strategies to secure affected applications.
