VendorsBladexspringbladeany version
Vulnerabilities

Bladex Springblade any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

4CVEs
CVE-2020-16165
The DAO/DTO implementation in SpringBlade through 2.7.1 allows SQL Injection in an ORDER BY clause. This is related to the /api/blade-log/api/list ascs and desc parameters.
Published 2020-07-30 · Modified
9.8EPSS 0.012
CVE-2023-47458
An issue in SpringBlade v.3.7.0 and before allows a remote attacker to escalate privileges via the lack of permissions control framework.
Published 2024-01-02 · Modified
9.8EPSS 0.006
CVE-2024-8023
chillzhuang SpringBlade list sql injection
Published 2024-08-20 · Analyzed
9.8EPSS 0.006
CVE-2023-40788
SpringBlade <=V3.6.0 is vulnerable to Incorrect Access Control due to incorrect configuration in the default gateway resulting in unauthorized access to error logs
Published 2023-09-18 · Modified
5.3EPSS 0.008