Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Liaojialin

Researcher fromJD Security SHENYI Team
#40989of 53,632
6.5Total CVSS
Vulnerabilities · 1
PT-2026-38598
6.5
2026-05-07
Unknown · Jeecg-Boot · CVE-2026-8114
**Name of the Vulnerable Software and Affected Versions** JeecgBoot versions prior to 3.9.2 **Description** An issue exists in the JSON Object Handler component where the manipulation of the `condition` argument in the '/sys/dict/loadTreeData' endpoint allows for remote SQL injection. SQL injection is a technique where an attacker inserts malicious SQL statements into a query, potentially allowing them to manipulate or access the database. **Recommendations** Update to a version newer than 3.9.1. As a temporary workaround, restrict access to the '/sys/dict/loadTreeData' endpoint or avoid using the `condition` parameter until the update is applied.