CVE-2023-34659: jeecg-boot 3.5.0 and 3.5.1 have a SQL injection vulnerability the id parameter of the /jeecg-boot/jmreport/show interface.

Description

jeecg-boot 3.5.0 and 3.5.1 have a SQL injection vulnerability the id parameter of the /jeecg-boot/jmreport/show interface.

Classification

CVE ID: CVE-2023-34659

Affected Products

Vendor: n/a

Product: n/a

Nuclei Template

http/cves/2023/CVE-2023-34659.yaml

Exploit Prediction Scoring System (EPSS)

EPSS Score: 20.32% (probability of being exploited)

EPSS Percentile: 96.42% (scored less or equal to compared to others)

EPSS Date: 2025-02-04 (when was this score calculated)

References

https://github.com/jeecgboot/jeecg-boot/issues/4976

Timeline