jeecg-boot Sleep Command SysDictMapper.java sql injection
CVE-2023-1741

9.8CRITICAL

Key Information:

Vendor

Jeecg

Vendor
CVE Published:
30 March 2023

What is CVE-2023-1741?

A vulnerability exists in Jeecg-Boot 3.5.0, specifically within the Sleep Command Handler's SysDictMapper.java file. This issue allows for SQL injection attacks, which can be executed remotely. The exploit has been made public, potentially enabling attackers to manipulate database queries without proper authorization, posing significant risks to data integrity and confidentiality.

Affected Version(s)

jeecg-boot 3.5.0

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

xuanshao (VulDB User)
.