In SpringBlade V3.6.0 when executing SQL query, the parameters submitted by the user are not wrapped in quotation marks, which leads to SQL injection.
CVSS
No CVSS.
References
Configurations
No configuration.
Information
Published : 2023-08-29 13:15
Updated : 2023-08-29 13:34
NVD link : CVE-2023-40787
Mitre link : CVE-2023-40787
JSON object : View
Products Affected
No product.
CWE
No CWE.
