-
Notifications
You must be signed in to change notification settings - Fork 15.5k
Closed
Description
版本号:
3.1.0
问题描述:
字典接口存在SQL注入风险
截图&代码:
https://github.com/jeecgboot/jeecg-boot/blob/2e90f73da26992cf1bb8cc4e699d780c45a3c1b2/jeecg-boot/jeecg-boot-module-system/src/main/java/org/jeecg/modules/system/service/impl/SysDictServiceImpl.java#L304-L311
https://github.com/jeecgboot/jeecg-boot/blob/2e90f73da26992cf1bb8cc4e699d780c45a3c1b2/jeecg-boot/jeecg-boot-module-system/src/main/java/org/jeecg/modules/system/mapper/xml/SysDictMapper.xml#L171-L185
# 请求路径示例
/jeecg-boot/sys/dict/loadDict/mysql.user,user,host,1%3C%3E(select%20user())?_t=1652851257&pageSize=10&keyword=
Activity
zhangdaiscott commentedon May 18, 2022
我们代码加了过滤,你能执行成功?
Nguyendream commentedon May 18, 2022
使用以下组件能执行
curl执行
zhangdaiscott commentedon May 24, 2022
已经修复,下个版本发