HTTP RULE(RULE ID:338893)

Rule General Information
Release Date: 2025-05-14
Rule Name: Jeecg-boot queryTableData SQL Injection Vulnerability (CVE-2022-45205)
Severity: High
CVE ID: CVE-2022-45205
Rule Protection Details
Description: Jeecg-boot v3.4.3 was discovered to contain a SQL injection vulnerability via the component /sys/dict/queryTableData.
Impact: An attacker can inject arbitrary sql commands to view or change the database of the target by exploiting the vulnerability successfully.
Affected OS: Windows, Linux, Others
Reference: http://jeecg-boot.com
https://github.com/jeecgboot/jeecg-boot/issues/4128
Solutions
Please refer to announcements or patches release by the vendor: https://github.com/jeecgboot/jeecg-boot/issues/4128