Vulnerability Description
SQL injection vulnerbility in jeecgboot jeecg-boot v 3.0, 3.5.3 that allows a remote attacker to execute arbitrary code via a crafted request to the report/jeecgboot/jmreport/queryFieldBySql component.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Jeecg | Jeecg Boot | 3.0 |
Related Weaknesses (CWE)
References
- https://github.com/Zone1-Z/CVE-2023-40989/blob/main/CVE-2023-40989Third Party Advisory
- https://github.com/Zone1-Z/CVE-2023-40989/blob/main/CVE-2023-40989Third Party Advisory
FAQ
What is CVE-2023-40989?
CVE-2023-40989 is a vulnerability with a CVSS score of 9.8 (CRITICAL). SQL injection vulnerbility in jeecgboot jeecg-boot v 3.0, 3.5.3 that allows a remote attacker to execute arbitrary code via a crafted request to the report/jeecgboot/jmreport/queryFieldBySql component...
How severe is CVE-2023-40989?
CVE-2023-40989 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2023-40989?
Check the references section above for vendor advisories and patch information. Affected products include: Jeecg Jeecg Boot.