MEDIUM
Jeesite 1.2.7 is affected by: SQL Injection
Published Jul 23, 2019
6.5
MEDIUMCVSS 3.0
EPSS 1.16%
Description
Jeesite 1.2.7 is affected by: SQL Injection. The impact is: sensitive information disclosure. The component is: updateProcInsIdByBusinessId() function in src/main/java/com.thinkgem.jeesite/modules/act/ActDao.java has SQL Injection vulnerability. The attack vector is: network connectivity,authenticated. The fixed version is: 4.0 and later.
Affected products
-
- Version 1.2.7 [fixed: 4.0 and later]StatusaffectedConstraints-
- Version
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (1)
- https://github.com/thinkgem/jeesite/blob/master/src/main/java/com/thinkgem/jeesite/modules/act/dao/ActDao.java x_refsource_MISCThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://github.com/thinkgem/jeesite/blob/master/src/main/java/com/thinkgem/jeesite/modules/act/dao/ActDao.java | x_refsource_MISCThird Party Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner dwf
Published Jul 23, 2019
Updated Aug 5, 2024
Reserved Mar 20, 2019
Link CVE-2019-1010201
CISA Vulnrichment
Updated n/a