VendorsJEECGjeecg_boot3.5.1
Vulnerabilities

JEECG Boot 3.5.1

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3CVEs
CVE-2023-38992
jeecg-boot v3.5.1 was discovered to contain a SQL injection vulnerability via the title parameter at /sys/dict/loadTreeData.
Published 2023-07-28 · Modified
9.8EPSS 0.734
CVE-2023-34659
jeecg-boot 3.5.0 and 3.5.1 have a SQL injection vulnerability the id parameter of the /jeecg-boot/jmreport/show interface.
Published 2023-06-16 · Modified
9.8EPSS 0.125
CVE-2023-34660
jjeecg-boot V3.5.0 has an unauthorized arbitrary file upload in /jeecg-boot/jmreport/upload interface.
Published 2023-06-16 · Modified
6.5EPSS 0.006