PT-2023-20027 · Unknown · Mybatis Plus

Published

2023-04-05

·

Updated

2024-08-02

·

CVE-2023-25330

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Mybatis plus versions prior to 3.5.3.1
Description A SQL injection issue allows remote attackers to execute arbitrary SQL commands via the tenant ID value. This can occur in misconfigured applications. The documentation provides guidance on developing applications that avoid SQL injection.
Recommendations For versions prior to 3.5.3.1, update to version 3.5.3.1 or later to resolve the issue. As a temporary workaround, consider restricting access to the tenant ID value to minimize the risk of exploitation. Ensure that applications are properly configured to avoid SQL injection vulnerabilities.

Exploit

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2023-25330
GHSA-32QQ-M9FH-F74W
OESA-2023-1996
OESA-2023-1997
OESA-2023-1998

Affected Products

Mybatis Plus