PT-2026-23883 · Unknown · Jeecg-Boot
Saul1213
·
Published
2026-03-07
·
Updated
2026-03-08
·
CVE-2026-3672
CVSS v2.0
6.5
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
JeecgBoot versions up to 3.9.1
Description
A flaw exists within JeecgBoot that allows for SQL injection. This issue is located in the
isExistSqlInjectKeyword function within the /jeecg-boot/sys/api/getDictItems file. Successful exploitation could occur remotely. The details of the exploit have been publicly disclosed.Recommendations
Update JeecgBoot to a version beyond 3.9.1.
Exploit
Fix
Special Elements Injection
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Jeecg-Boot