CVE-2023-43192
Severity CVSS v4.0:
Pending analysis
Type:
CWE-89
SQL Injection
Publication date:
27/09/2023
Last modified:
26/10/2023
Description
SQL injection can exist in a newly created part of the SpringbootCMS 1.0 background, and the parameters submitted by users are not filtered. As a result, special characters in parameters destroy the original logic of SQL statements. Attackers can use this vulnerability to execute any SQL statement.
Impact
Base Score 3.x
8.80
Severity 3.x
HIGH
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:a:jrecms:springbootcms:1.0:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page