RULE(RULE ID:338291)

Rule General Information
Release Date: 2024-08-06
Rule Name: SpringBlade Frame menu interface SQL Injection Vulnerability
Severity:
CVE ID:
Rule Protection Details
Description: SpringBlade is a modern enterprise application development framework based on Spring Boot, which provides a series of general microservice solutions to simplify the development process and accelerate the development and deployment of enterprise applications. The SpringBlade background framework menu/list has an SQL injection vulnerability. In addition to using the SQL injection vulnerability to obtain information in the database, attackers can even write trojans to the server under high permissions to further obtain server system permissions.
Impact: An attacker can inject arbitrary sql commands to view or change the database of the target by exploiting the vulnerability successfully.
Affected OS: Windows, Linux, Others
Reference:
Solutions
Please contact the software vendor to update the software patch.