
CVE-2023-1454 jeecg-boot Unauthorized SQL injection vulnerability
CVE-2023-1454 jeecg-boot Unauthorized SQL injection vulnerability
JeecgBoot is a low-code development platform based on a code generator. The latest unauthorized SQL injection in the Java low-code platform jeecg-boot(v3.5.0) for enterprise web applications. In addition to exploiting the SQL injection vulnerability to obtain database information (such as admin backend passwords, site user personal information), attackers can even write a trojan to the server under high privileges to further gain server system permissions.