{"id":"GHSA-23xf-5535-62v5","summary":"jeecg-boot vulnerable to SQL injection","details":"jeecg-boot 3.5.0 is vulnerable to SQL injection from functionality of the file `SysDictMapper.java` of the component `Sleep Command Handler`. The attack can be launched remotely and the exploit has been disclosed to the public and may be used.","aliases":["CVE-2023-1741"],"modified":"2023-11-08T04:11:19.079608Z","published":"2023-03-31T00:30:18Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2023-04-07T22:09:37Z","nvd_published_at":"2023-03-30T22:15:00Z","cwe_ids":["CWE-89"],"severity":"CRITICAL"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-1741"},{"type":"PACKAGE","url":"https://github.com/jeecgboot/jeecg-boot"},{"type":"WEB","url":"https://github.com/private-null/report/blob/main/README.md"},{"type":"WEB","url":"https://vuldb.com/?ctiid.224629"},{"type":"WEB","url":"https://vuldb.com/?id.224629"}],"affected":[{"package":{"name":"org.jeecgframework.boot:jeecg-boot-parent","ecosystem":"Maven","purl":"pkg:maven/org.jeecgframework.boot/jeecg-boot-parent"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"3.5.0"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/03/GHSA-23xf-5535-62v5/GHSA-23xf-5535-62v5.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}