Unknown · Jeecg-Boot · CVE-2023-42268
**Name of the Vulnerable Software and Affected Versions**
Jeecg boot versions up to 3.5.3
**Description**
A SQL injection vulnerability was discovered in Jeecg boot via the component "/jeecg-boot/jmreport/show". This issue allows for SQL injection attacks, potentially leading to unauthorized access to sensitive data.
**Recommendations**
For versions up to 3.5.3, update to a version later than 3.5.3 to resolve the SQL injection vulnerability. As a temporary workaround, consider restricting access to the "/jeecg-boot/jmreport/show" component until a patch is available.