PT-2024-26312 · J2Eefast · J2Eefast

Published

2024-05-23

·

Updated

2024-11-04

·

CVE-2024-35083

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions J2EEFAST version 2.7.0
Description A SQL injection issue was discovered via the findPage function in SysLoginInfoMapper.xml. This allows for potential exploitation.
Recommendations For J2EEFAST version 2.7.0, consider restricting access to the findPage function in SysLoginInfoMapper.xml until a patch is available. At the moment, there is no information about a newer version that contains a fix for this issue.

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2024-35083

Affected Products

J2Eefast