{"id":"GHSA-62pr-54gv-vg5g","summary":"SpringBlade vulnerable to SQL injection","details":"In SpringBlade V3.6.0 when executing SQL query, the parameters submitted by the user are not wrapped in quotation marks, which leads to SQL injection.","aliases":["CVE-2023-40787"],"modified":"2023-11-08T04:13:22.843692Z","published":"2023-08-29T15:31:51Z","database_specific":{"github_reviewed_at":"2023-08-31T18:33:40Z","nvd_published_at":"2023-08-29T13:15:53Z","cwe_ids":["CWE-89"],"severity":"HIGH","github_reviewed":true},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-40787"},{"type":"WEB","url":"https://gist.github.com/kaliwin/9d6cf58bb6ec06765cdf7b75e13ee460"},{"type":"PACKAGE","url":"https://github.com/chillzhuang/blade-tool"},{"type":"WEB","url":"https://sword.bladex.cn"}],"affected":[{"package":{"name":"org.springblade:blade-core-tool","ecosystem":"Maven","purl":"pkg:maven/org.springblade/blade-core-tool"},"versions":["3.6.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/08/GHSA-62pr-54gv-vg5g/GHSA-62pr-54gv-vg5g.json"}}],"schema_version":"1.9.0"}